An evolution of the Content Security Policy specification, allowing developers to create a whitelist of sources of trusted content, and instructing the browser to only execute or render resources from those sources.

Specification

Established standard

Status in Chromium

Blink


Enabled by default in:

  • Chrome for desktop release 40
  • Chrome for Android release 40
  • Android WebView release 40

Consensus & Standardization

After a feature ships in Chrome, the values listed here are not guaranteed to be up to date.

Owners

Search tags

csp,

Last updated on 2020-11-09