FM Field Manual smhansen.dev

FM 9-05 Chapter 9 · Web and developer

Content-Security-Policy

Explain a CSP directive by directive, flag risky sources and missing directives, or build a new policy.

Local only Runs in your browser. Nothing you enter leaves this page.

Examples

Directives without their own value fall back to default-src, but base-uri, form-action and frame-ancestors do not. When a page has a header and a meta policy, both apply and the stricter wins. The examples show this site's own policy (hashes shortened).

  • No entry in this manual matches “”.

↑ ↓ move · Enter open · Esc close