Content Security Policy 1.0
Content Security Policy 1.0
Mitigate cross-site scripting attacks by whitelisting allowed sources of script, style, and other resources.
Spec | http://www.w3.org/TR/2012/CR-CSP-20121115/ |
---|---|
Status | W3C Candidate Recommendation |
IE | Edge | Firefox | Chrome | Safari | Opera |
---|---|---|---|---|---|
57 | 62 | ||||
56 | 61 | TP | 48 | ||
16 | 55 | 60 | 11 | 47 | |
11 (1) | 15 | 54 | 59 | 10.1 | 46 |
10 (1) | 14 | 53 | 58 | 10 | 45 |
9 | 13 | 52 | 57 | 9.1 | 44 |
8 | 12 | 51 | 56 | 9 | 43 |
Show all | |||||
7 | 50 | 55 | 8 | 42 | |
6 | 49 | 54 | 7.1 | 41 | |
5.5 | 48 | 53 | 7 | 40 | |
47 | 52 | 6.1 (2) | 39 | ||
46 | 51 | 6 (2) | 38 | ||
45 | 50 | 5.1 (2) | 37 | ||
44 | 49 | 5 | 36 | ||
43 | 48 | 4 | 35 | ||
42 | 47 | 3.2 | 34 | ||
41 | 46 | 3.1 | 33 | ||
40 | 45 | 32 | |||
39 | 44 | 31 | |||
38 | 43 | 30 | |||
37 | 42 | 29 | |||
36 | 41 | 28 | |||
35 | 40 | 27 | |||
34 | 39 | 26 | |||
33 | 38 | 25 | |||
32 | 37 | 24 | |||
31 | 36 | 23 | |||
30 | 35 | 22 | |||
29 | 34 | 21 | |||
28 | 33 | 20 | |||
27 | 32 | 19 | |||
26 | 31 | 18 | |||
25 | 30 | 17 | |||
24 | 29 | 16 | |||
23 | 28 | 15 | |||
22 (1) | 27 | 12.1 | |||
21 (1) | 26 | 12 | |||
20 (1) | 25 | 11.6 | |||
19 (1) | 24 (2) | 11.5 | |||
18 (1) | 23 (2) | 11.1 | |||
17 (1) | 22 (2) | 11 | |||
16 (1) | 21 (2) | 10.6 | |||
15 (1) | 20 (2) | 10.5 | |||
14 (1) | 19 (2) | 10.0-10.1 | |||
13 (1) | 18 (2) | 9.5-9.6 | |||
12 (1) | 17 (2) | 9 | |||
11 (1) | 16 (2) | ||||
10 (1) | 15 (2) | ||||
9 (1) | 14 (2) | ||||
8 (1) | 13 | ||||
7 (1) | 12 | ||||
6 (1) | 11 | ||||
5 (1) | 10 | ||||
4 (1) | 9 | ||||
3.6 | 8 | ||||
3.5 | 7 | ||||
3 | 6 | ||||
2 | 5 | ||||
4 |
iOS Safari | Opera Mini | Android Browser | Blackberry Browser | Opera Mobile | Android Chrome | Android Firefox | IE Mobile | Android UC Browser | Samsung Internet | QQ Browser | Baidu Browser |
---|---|---|---|---|---|---|---|---|---|---|---|
11 | |||||||||||
10.3 | all | 56 | 10 (2) | 37 | 59 | 54 | 11 (1) | 11.4 (2) | 5 | 1.2 | 7.12 |
10.0-10.2 | 4.4.3-4.4.4 | 7 | 12.1 | 10 (1) | 4 | ||||||
9.3 | 4.4 | 12 | |||||||||
9.0-9.2 | 4.2-4.3 | 11.5 | |||||||||
Show all | |||||||||||
8.1-8.4 | 4.1 | 11.1 | |||||||||
8 | 4 | 11 | |||||||||
7.0-7.1 | 3 | 10 | |||||||||
6.0-6.1 (2) | 2.3 | ||||||||||
5.0-5.1 (2) | 2.2 | ||||||||||
4.2-4.3 | 2.1 | ||||||||||
4.0-4.1 | |||||||||||
3.2 |
Notes
The standard HTTP header is Content-Security-Policy
which is used unless otherwise noted.
Supported through the
X-Content-Security-Policy
headerSupported through the
X-Webkit-CSP
header
Bugs
Partial support in Internet Explorer 10-11 refers to the browser only supporting the 'sandbox' directive by using the
X-Content-Security-Policy
header.Partial support in iOS Safari 5.0-5.1 refers to the browser recognizing the
X-Webkit-CSP
header but failing to handle complex cases correctly, often resulting in broken pages.Chrome for iOS fails to render pages without a connect-src 'self' policy.
Resources
- HTML5Rocks article
- CSP Examples & Quick Reference
- Mozilla Developer Network (MDN) documentation - Content Security Policy
Data by caniuse.com
Licensed under the Creative Commons Attribution License v4.0.
http://caniuse.com/#feat=contentsecuritypolicy