Content Security Policy 1.0

Content Security Policy 1.0

Mitigate cross-site scripting attacks by whitelisting allowed sources of script, style, and other resources.

Spec http://www.w3.org/TR/2012/CR-CSP-20121115/
Status W3C Candidate Recommendation
IE Edge Firefox Chrome Safari Opera
    57 62    
    56 61 TP 48
  16 55 60 11 47
11 (1) 15 54 59 10.1 46
10 (1) 14 53 58 10 45
9 13 52 57 9.1 44
8 12 51 56 9 43
Show all
7   50 55 8 42
6   49 54 7.1 41
5.5   48 53 7 40
    47 52 6.1 (2) 39
    46 51 6 (2) 38
    45 50 5.1 (2) 37
    44 49 5 36
    43 48 4 35
    42 47 3.2 34
    41 46 3.1 33
    40 45   32
    39 44   31
    38 43   30
    37 42   29
    36 41   28
    35 40   27
    34 39   26
    33 38   25
    32 37   24
    31 36   23
    30 35   22
    29 34   21
    28 33   20
    27 32   19
    26 31   18
    25 30   17
    24 29   16
    23 28   15
    22 (1) 27   12.1
    21 (1) 26   12
    20 (1) 25   11.6
    19 (1) 24 (2)   11.5
    18 (1) 23 (2)   11.1
    17 (1) 22 (2)   11
    16 (1) 21 (2)   10.6
    15 (1) 20 (2)   10.5
    14 (1) 19 (2)   10.0-10.1
    13 (1) 18 (2)   9.5-9.6
    12 (1) 17 (2)   9
    11 (1) 16 (2)    
    10 (1) 15 (2)    
    9 (1) 14 (2)    
    8 (1) 13    
    7 (1) 12    
    6 (1) 11    
    5 (1) 10    
    4 (1) 9    
    3.6 8    
    3.5 7    
    3 6    
    2 5    
      4    
iOS Safari Opera Mini Android Browser Blackberry Browser Opera Mobile Android Chrome Android Firefox IE Mobile Android UC Browser Samsung Internet QQ Browser Baidu Browser
11                      
10.3 all 56 10 (2) 37 59 54 11 (1) 11.4 (2) 5 1.2 7.12
10.0-10.2   4.4.3-4.4.4 7 12.1     10 (1)   4    
9.3   4.4   12              
9.0-9.2   4.2-4.3   11.5              
Show all
8.1-8.4   4.1   11.1              
8   4   11              
7.0-7.1   3   10              
6.0-6.1 (2)   2.3                  
5.0-5.1 (2)   2.2                  
4.2-4.3   2.1                  
4.0-4.1                      
3.2                      

Notes

The standard HTTP header is Content-Security-Policy which is used unless otherwise noted.

  1. Supported through the X-Content-Security-Policy header

  2. Supported through the X-Webkit-CSP header

Bugs

  • Partial support in Internet Explorer 10-11 refers to the browser only supporting the 'sandbox' directive by using the X-Content-Security-Policy header.

  • Partial support in iOS Safari 5.0-5.1 refers to the browser recognizing the X-Webkit-CSP header but failing to handle complex cases correctly, often resulting in broken pages.

  • Chrome for iOS fails to render pages without a connect-src 'self' policy.

Resources

Data by caniuse.com
Licensed under the Creative Commons Attribution License v4.0.
http://caniuse.com/#feat=contentsecuritypolicy

在线笔记
App下载
App下载

扫描二维码

下载编程狮App

公众号
微信公众号

编程狮公众号

意见反馈
返回顶部