contentsecuritypolicy.json 6.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380
  1. {
  2. "title":"Content Security Policy 1.0",
  3. "description":"Mitigate cross-site scripting attacks by whitelisting allowed sources of script, style, and other resources.",
  4. "spec":"https://www.w3.org/TR/2012/CR-CSP-20121115/",
  5. "status":"cr",
  6. "links":[
  7. {
  8. "url":"https://www.html5rocks.com/en/tutorials/security/content-security-policy/",
  9. "title":"HTML5Rocks article"
  10. },
  11. {
  12. "url":"http://content-security-policy.com/",
  13. "title":"CSP Examples & Quick Reference"
  14. },
  15. {
  16. "url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP",
  17. "title":"MDN Web Docs - Content Security Policy"
  18. }
  19. ],
  20. "bugs":[
  21. {
  22. "description":"Partial support in Internet Explorer 10-11 refers to the browser only supporting the 'sandbox' directive by using the `X-Content-Security-Policy` header."
  23. },
  24. {
  25. "description":"Partial support in iOS Safari 5.0-5.1 refers to the browser recognizing the `X-WebKit-CSP` header but failing to handle complex cases correctly, often resulting in broken pages."
  26. },
  27. {
  28. "description":"Chrome for iOS fails to render pages without a [connect-src 'self'](https://code.google.com/p/chromium/issues/detail?id=322497) policy."
  29. }
  30. ],
  31. "categories":[
  32. "Security"
  33. ],
  34. "stats":{
  35. "ie":{
  36. "5.5":"n",
  37. "6":"n",
  38. "7":"n",
  39. "8":"n",
  40. "9":"n",
  41. "10":"a #1",
  42. "11":"a #1"
  43. },
  44. "edge":{
  45. "12":"y",
  46. "13":"y",
  47. "14":"y",
  48. "15":"y",
  49. "16":"y",
  50. "17":"y",
  51. "18":"y",
  52. "76":"y"
  53. },
  54. "firefox":{
  55. "2":"n",
  56. "3":"n",
  57. "3.5":"n",
  58. "3.6":"n",
  59. "4":"y #1",
  60. "5":"y #1",
  61. "6":"y #1",
  62. "7":"y #1",
  63. "8":"y #1",
  64. "9":"y #1",
  65. "10":"y #1",
  66. "11":"y #1",
  67. "12":"y #1",
  68. "13":"y #1",
  69. "14":"y #1",
  70. "15":"y #1",
  71. "16":"y #1",
  72. "17":"y #1",
  73. "18":"y #1",
  74. "19":"y #1",
  75. "20":"y #1",
  76. "21":"y #1",
  77. "22":"y #1",
  78. "23":"y",
  79. "24":"y",
  80. "25":"y",
  81. "26":"y",
  82. "27":"y",
  83. "28":"y",
  84. "29":"y",
  85. "30":"y",
  86. "31":"y",
  87. "32":"y",
  88. "33":"y",
  89. "34":"y",
  90. "35":"y",
  91. "36":"y",
  92. "37":"y",
  93. "38":"y",
  94. "39":"y",
  95. "40":"y",
  96. "41":"y",
  97. "42":"y",
  98. "43":"y",
  99. "44":"y",
  100. "45":"y",
  101. "46":"y",
  102. "47":"y",
  103. "48":"y",
  104. "49":"y",
  105. "50":"y",
  106. "51":"y",
  107. "52":"y",
  108. "53":"y",
  109. "54":"y",
  110. "55":"y",
  111. "56":"y",
  112. "57":"y",
  113. "58":"y",
  114. "59":"y",
  115. "60":"y",
  116. "61":"y",
  117. "62":"y",
  118. "63":"y",
  119. "64":"y",
  120. "65":"y",
  121. "66":"y",
  122. "67":"y",
  123. "68":"y",
  124. "69":"y",
  125. "70":"y",
  126. "71":"y"
  127. },
  128. "chrome":{
  129. "4":"n",
  130. "5":"n",
  131. "6":"n",
  132. "7":"n",
  133. "8":"n",
  134. "9":"n",
  135. "10":"n",
  136. "11":"n",
  137. "12":"n",
  138. "13":"n",
  139. "14":"y #2",
  140. "15":"y #2",
  141. "16":"y #2",
  142. "17":"y #2",
  143. "18":"y #2",
  144. "19":"y #2",
  145. "20":"y #2",
  146. "21":"y #2",
  147. "22":"y #2",
  148. "23":"y #2",
  149. "24":"y #2",
  150. "25":"y",
  151. "26":"y",
  152. "27":"y",
  153. "28":"y",
  154. "29":"y",
  155. "30":"y",
  156. "31":"y",
  157. "32":"y",
  158. "33":"y",
  159. "34":"y",
  160. "35":"y",
  161. "36":"y",
  162. "37":"y",
  163. "38":"y",
  164. "39":"y",
  165. "40":"y",
  166. "41":"y",
  167. "42":"y",
  168. "43":"y",
  169. "44":"y",
  170. "45":"y",
  171. "46":"y",
  172. "47":"y",
  173. "48":"y",
  174. "49":"y",
  175. "50":"y",
  176. "51":"y",
  177. "52":"y",
  178. "53":"y",
  179. "54":"y",
  180. "55":"y",
  181. "56":"y",
  182. "57":"y",
  183. "58":"y",
  184. "59":"y",
  185. "60":"y",
  186. "61":"y",
  187. "62":"y",
  188. "63":"y",
  189. "64":"y",
  190. "65":"y",
  191. "66":"y",
  192. "67":"y",
  193. "68":"y",
  194. "69":"y",
  195. "70":"y",
  196. "71":"y",
  197. "72":"y",
  198. "73":"y",
  199. "74":"y",
  200. "75":"y",
  201. "76":"y",
  202. "77":"y",
  203. "78":"y",
  204. "79":"y"
  205. },
  206. "safari":{
  207. "3.1":"n",
  208. "3.2":"n",
  209. "4":"n",
  210. "5":"n",
  211. "5.1":"a #2",
  212. "6":"y #2",
  213. "6.1":"y #2",
  214. "7":"y",
  215. "7.1":"y",
  216. "8":"y",
  217. "9":"y",
  218. "9.1":"y",
  219. "10":"y",
  220. "10.1":"y",
  221. "11":"y",
  222. "11.1":"y",
  223. "12":"y",
  224. "12.1":"y",
  225. "13":"y",
  226. "TP":"y"
  227. },
  228. "opera":{
  229. "9":"n",
  230. "9.5-9.6":"n",
  231. "10.0-10.1":"n",
  232. "10.5":"n",
  233. "10.6":"n",
  234. "11":"n",
  235. "11.1":"n",
  236. "11.5":"n",
  237. "11.6":"n",
  238. "12":"n",
  239. "12.1":"n",
  240. "15":"y",
  241. "16":"y",
  242. "17":"y",
  243. "18":"y",
  244. "19":"y",
  245. "20":"y",
  246. "21":"y",
  247. "22":"y",
  248. "23":"y",
  249. "24":"y",
  250. "25":"y",
  251. "26":"y",
  252. "27":"y",
  253. "28":"y",
  254. "29":"y",
  255. "30":"y",
  256. "31":"y",
  257. "32":"y",
  258. "33":"y",
  259. "34":"y",
  260. "35":"y",
  261. "36":"y",
  262. "37":"y",
  263. "38":"y",
  264. "39":"y",
  265. "40":"y",
  266. "41":"y",
  267. "42":"y",
  268. "43":"y",
  269. "44":"y",
  270. "45":"y",
  271. "46":"y",
  272. "47":"y",
  273. "48":"y",
  274. "49":"y",
  275. "50":"y",
  276. "51":"y",
  277. "52":"y",
  278. "53":"y",
  279. "54":"y",
  280. "55":"y",
  281. "56":"y",
  282. "57":"y",
  283. "58":"y",
  284. "60":"y",
  285. "62":"y"
  286. },
  287. "ios_saf":{
  288. "3.2":"n",
  289. "4.0-4.1":"n",
  290. "4.2-4.3":"n",
  291. "5.0-5.1":"a #2",
  292. "6.0-6.1":"y #2",
  293. "7.0-7.1":"y",
  294. "8":"y",
  295. "8.1-8.4":"y",
  296. "9.0-9.2":"y",
  297. "9.3":"y",
  298. "10.0-10.2":"y",
  299. "10.3":"y",
  300. "11.0-11.2":"y",
  301. "11.3-11.4":"y",
  302. "12.0-12.1":"y",
  303. "12.2-12.3":"y",
  304. "13":"y"
  305. },
  306. "op_mini":{
  307. "all":"n"
  308. },
  309. "android":{
  310. "2.1":"n",
  311. "2.2":"n",
  312. "2.3":"n",
  313. "3":"n",
  314. "4":"n",
  315. "4.1":"n",
  316. "4.2-4.3":"n",
  317. "4.4":"y",
  318. "4.4.3-4.4.4":"y",
  319. "67":"y"
  320. },
  321. "bb":{
  322. "7":"n",
  323. "10":"y #2"
  324. },
  325. "op_mob":{
  326. "10":"n",
  327. "11":"n",
  328. "11.1":"n",
  329. "11.5":"n",
  330. "12":"n",
  331. "12.1":"n",
  332. "46":"y"
  333. },
  334. "and_chr":{
  335. "75":"y"
  336. },
  337. "and_ff":{
  338. "67":"y"
  339. },
  340. "ie_mob":{
  341. "10":"a #1",
  342. "11":"a #1"
  343. },
  344. "and_uc":{
  345. "12.12":"y #2"
  346. },
  347. "samsung":{
  348. "4":"y",
  349. "5.0-5.4":"y",
  350. "6.2-6.4":"y",
  351. "7.2-7.4":"y",
  352. "8.2":"y",
  353. "9.2":"y"
  354. },
  355. "and_qq":{
  356. "1.2":"y"
  357. },
  358. "baidu":{
  359. "7.12":"y"
  360. },
  361. "kaios":{
  362. "2.5":"y"
  363. }
  364. },
  365. "notes":"The standard HTTP header is `Content-Security-Policy` which is used unless otherwise noted.",
  366. "notes_by_num":{
  367. "1":"Supported through the `X-Content-Security-Policy` header",
  368. "2":"Supported through the `X-WebKit-CSP` header"
  369. },
  370. "usage_perc_y":94.69,
  371. "usage_perc_a":2.18,
  372. "ucprefix":false,
  373. "parent":"",
  374. "keywords":"csp,security,header",
  375. "ie_id":"contentsecuritypolicy",
  376. "chrome_id":"5205088045891584",
  377. "firefox_id":"",
  378. "webkit_id":"",
  379. "shown":true
  380. }