|
| 1 | +draft_date: 2025-06-23 |
| 2 | +name: Content Security Policy Level 3 |
| 3 | +description: TODO |
| 4 | +spec: https://w3c.github.io/webappsec-csp/ |
| 5 | +compat_features: |
| 6 | + - http.headers.Content-Security-Policy.script-src.trusted-types-eval |
| 7 | + |
| 8 | +# The following features in the spec are already part of web-features: |
| 9 | +# - Reporting API: |
| 10 | +# - api.CSPViolationReportBody |
| 11 | +# - api.CSPViolationReportBody.blockedURL |
| 12 | +# - api.CSPViolationReportBody.columnNumber |
| 13 | +# - api.CSPViolationReportBody.disposition |
| 14 | +# - api.CSPViolationReportBody.documentURL |
| 15 | +# - api.CSPViolationReportBody.effectiveDirective |
| 16 | +# - api.CSPViolationReportBody.lineNumber |
| 17 | +# - api.CSPViolationReportBody.originalPolicy |
| 18 | +# - api.CSPViolationReportBody.referrer |
| 19 | +# - api.CSPViolationReportBody.sample |
| 20 | +# - api.CSPViolationReportBody.sourceFile |
| 21 | +# - api.CSPViolationReportBody.statusCode |
| 22 | +# - api.CSPViolationReportBody.toJSON |
| 23 | +# - Content Security Policy (CSP): |
| 24 | +# - api.Element.securitypolicyviolation_event |
| 25 | +# - api.SecurityPolicyViolationEvent |
| 26 | +# - api.SecurityPolicyViolationEvent.SecurityPolicyViolationEvent |
| 27 | +# - api.SecurityPolicyViolationEvent.blockedURI |
| 28 | +# - api.SecurityPolicyViolationEvent.columnNumber |
| 29 | +# - api.SecurityPolicyViolationEvent.disposition |
| 30 | +# - api.SecurityPolicyViolationEvent.documentURI |
| 31 | +# - api.SecurityPolicyViolationEvent.effectiveDirective |
| 32 | +# - api.SecurityPolicyViolationEvent.lineNumber |
| 33 | +# - api.SecurityPolicyViolationEvent.originalPolicy |
| 34 | +# - api.SecurityPolicyViolationEvent.referrer |
| 35 | +# - api.SecurityPolicyViolationEvent.sample |
| 36 | +# - api.SecurityPolicyViolationEvent.sourceFile |
| 37 | +# - api.SecurityPolicyViolationEvent.statusCode |
| 38 | +# - api.SecurityPolicyViolationEvent.violatedDirective |
| 39 | +# - api.SecurityPolicyViolationEvent.worker_support |
| 40 | +# - api.WorkerGlobalScope.securitypolicyviolation_event |
| 41 | +# - http.headers.Content-Security-Policy |
| 42 | +# - http.headers.Content-Security-Policy.base-uri |
| 43 | +# - http.headers.Content-Security-Policy.child-src |
| 44 | +# - http.headers.Content-Security-Policy.connect-src |
| 45 | +# - http.headers.Content-Security-Policy.default-src |
| 46 | +# - http.headers.Content-Security-Policy.font-src |
| 47 | +# - http.headers.Content-Security-Policy.form-action |
| 48 | +# - http.headers.Content-Security-Policy.frame-ancestors |
| 49 | +# - http.headers.Content-Security-Policy.frame-src |
| 50 | +# - http.headers.Content-Security-Policy.img-src |
| 51 | +# - http.headers.Content-Security-Policy.manifest-src |
| 52 | +# - http.headers.Content-Security-Policy.media-src |
| 53 | +# - http.headers.Content-Security-Policy.meta-element-support |
| 54 | +# - http.headers.Content-Security-Policy.object-src |
| 55 | +# - http.headers.Content-Security-Policy.report-sample |
| 56 | +# - http.headers.Content-Security-Policy.report-to |
| 57 | +# - http.headers.Content-Security-Policy.sandbox |
| 58 | +# - http.headers.Content-Security-Policy.script-src |
| 59 | +# - http.headers.Content-Security-Policy.script-src.external_scripts |
| 60 | +# - http.headers.Content-Security-Policy.script-src.wasm-unsafe-eval |
| 61 | +# - http.headers.Content-Security-Policy.script-src-attr |
| 62 | +# - http.headers.Content-Security-Policy.script-src-elem |
| 63 | +# - http.headers.Content-Security-Policy.strict-dynamic |
| 64 | +# - http.headers.Content-Security-Policy.style-src |
| 65 | +# - http.headers.Content-Security-Policy.style-src-attr |
| 66 | +# - http.headers.Content-Security-Policy.style-src-elem |
| 67 | +# - http.headers.Content-Security-Policy.unsafe-hashes |
| 68 | +# - http.headers.Content-Security-Policy.worker-src |
| 69 | +# - http.headers.Content-Security-Policy.worker_support |
| 70 | +# - http.headers.Content-Security-Policy-Report-Only |
0 commit comments