contentsecuritypolicy.json 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558
  1. {
  2. "title":"Content Security Policy 1.0",
  3. "description":"Mitigate cross-site scripting attacks by only allowing certain sources of script, style, and other resources.",
  4. "spec":"https://www.w3.org/TR/2012/CR-CSP-20121115/",
  5. "status":"cr",
  6. "links":[
  7. {
  8. "url":"https://www.html5rocks.com/en/tutorials/security/content-security-policy/",
  9. "title":"HTML5Rocks article"
  10. },
  11. {
  12. "url":"https://content-security-policy.com/",
  13. "title":"CSP Examples & Quick Reference"
  14. },
  15. {
  16. "url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP",
  17. "title":"MDN Web Docs - Content Security Policy"
  18. }
  19. ],
  20. "bugs":[
  21. {
  22. "description":"Partial support in Internet Explorer 10-11 refers to the browser only supporting the 'sandbox' directive by using the `X-Content-Security-Policy` header."
  23. },
  24. {
  25. "description":"Partial support in iOS Safari 5.0-5.1 refers to the browser recognizing the `X-WebKit-CSP` header but failing to handle complex cases correctly, often resulting in broken pages."
  26. },
  27. {
  28. "description":"Chrome for iOS fails to render pages without a [connect-src 'self'](https://code.google.com/p/chromium/issues/detail?id=322497) policy."
  29. }
  30. ],
  31. "categories":[
  32. "Security"
  33. ],
  34. "stats":{
  35. "ie":{
  36. "5.5":"n",
  37. "6":"n",
  38. "7":"n",
  39. "8":"n",
  40. "9":"n",
  41. "10":"a #1",
  42. "11":"a #1"
  43. },
  44. "edge":{
  45. "12":"y",
  46. "13":"y",
  47. "14":"y",
  48. "15":"y",
  49. "16":"y",
  50. "17":"y",
  51. "18":"y",
  52. "79":"y",
  53. "80":"y",
  54. "81":"y",
  55. "83":"y",
  56. "84":"y",
  57. "85":"y",
  58. "86":"y",
  59. "87":"y",
  60. "88":"y",
  61. "89":"y",
  62. "90":"y",
  63. "91":"y",
  64. "92":"y",
  65. "93":"y",
  66. "94":"y",
  67. "95":"y",
  68. "96":"y",
  69. "97":"y",
  70. "98":"y",
  71. "99":"y",
  72. "100":"y",
  73. "101":"y",
  74. "102":"y",
  75. "103":"y",
  76. "104":"y",
  77. "105":"y",
  78. "106":"y",
  79. "107":"y",
  80. "108":"y",
  81. "109":"y",
  82. "110":"y"
  83. },
  84. "firefox":{
  85. "2":"n",
  86. "3":"n",
  87. "3.5":"n",
  88. "3.6":"n",
  89. "4":"y #1",
  90. "5":"y #1",
  91. "6":"y #1",
  92. "7":"y #1",
  93. "8":"y #1",
  94. "9":"y #1",
  95. "10":"y #1",
  96. "11":"y #1",
  97. "12":"y #1",
  98. "13":"y #1",
  99. "14":"y #1",
  100. "15":"y #1",
  101. "16":"y #1",
  102. "17":"y #1",
  103. "18":"y #1",
  104. "19":"y #1",
  105. "20":"y #1",
  106. "21":"y #1",
  107. "22":"y #1",
  108. "23":"y",
  109. "24":"y",
  110. "25":"y",
  111. "26":"y",
  112. "27":"y",
  113. "28":"y",
  114. "29":"y",
  115. "30":"y",
  116. "31":"y",
  117. "32":"y",
  118. "33":"y",
  119. "34":"y",
  120. "35":"y",
  121. "36":"y",
  122. "37":"y",
  123. "38":"y",
  124. "39":"y",
  125. "40":"y",
  126. "41":"y",
  127. "42":"y",
  128. "43":"y",
  129. "44":"y",
  130. "45":"y",
  131. "46":"y",
  132. "47":"y",
  133. "48":"y",
  134. "49":"y",
  135. "50":"y",
  136. "51":"y",
  137. "52":"y",
  138. "53":"y",
  139. "54":"y",
  140. "55":"y",
  141. "56":"y",
  142. "57":"y",
  143. "58":"y",
  144. "59":"y",
  145. "60":"y",
  146. "61":"y",
  147. "62":"y",
  148. "63":"y",
  149. "64":"y",
  150. "65":"y",
  151. "66":"y",
  152. "67":"y",
  153. "68":"y",
  154. "69":"y",
  155. "70":"y",
  156. "71":"y",
  157. "72":"y",
  158. "73":"y",
  159. "74":"y",
  160. "75":"y",
  161. "76":"y",
  162. "77":"y",
  163. "78":"y",
  164. "79":"y",
  165. "80":"y",
  166. "81":"y",
  167. "82":"y",
  168. "83":"y",
  169. "84":"y",
  170. "85":"y",
  171. "86":"y",
  172. "87":"y",
  173. "88":"y",
  174. "89":"y",
  175. "90":"y",
  176. "91":"y",
  177. "92":"y",
  178. "93":"y",
  179. "94":"y",
  180. "95":"y",
  181. "96":"y",
  182. "97":"y",
  183. "98":"y",
  184. "99":"y",
  185. "100":"y",
  186. "101":"y",
  187. "102":"y",
  188. "103":"y",
  189. "104":"y",
  190. "105":"y",
  191. "106":"y",
  192. "107":"y",
  193. "108":"y",
  194. "109":"y",
  195. "110":"y",
  196. "111":"y",
  197. "112":"y"
  198. },
  199. "chrome":{
  200. "4":"n",
  201. "5":"n",
  202. "6":"n",
  203. "7":"n",
  204. "8":"n",
  205. "9":"n",
  206. "10":"n",
  207. "11":"n",
  208. "12":"n",
  209. "13":"n",
  210. "14":"y #2",
  211. "15":"y #2",
  212. "16":"y #2",
  213. "17":"y #2",
  214. "18":"y #2",
  215. "19":"y #2",
  216. "20":"y #2",
  217. "21":"y #2",
  218. "22":"y #2",
  219. "23":"y #2",
  220. "24":"y #2",
  221. "25":"y",
  222. "26":"y",
  223. "27":"y",
  224. "28":"y",
  225. "29":"y",
  226. "30":"y",
  227. "31":"y",
  228. "32":"y",
  229. "33":"y",
  230. "34":"y",
  231. "35":"y",
  232. "36":"y",
  233. "37":"y",
  234. "38":"y",
  235. "39":"y",
  236. "40":"y",
  237. "41":"y",
  238. "42":"y",
  239. "43":"y",
  240. "44":"y",
  241. "45":"y",
  242. "46":"y",
  243. "47":"y",
  244. "48":"y",
  245. "49":"y",
  246. "50":"y",
  247. "51":"y",
  248. "52":"y",
  249. "53":"y",
  250. "54":"y",
  251. "55":"y",
  252. "56":"y",
  253. "57":"y",
  254. "58":"y",
  255. "59":"y",
  256. "60":"y",
  257. "61":"y",
  258. "62":"y",
  259. "63":"y",
  260. "64":"y",
  261. "65":"y",
  262. "66":"y",
  263. "67":"y",
  264. "68":"y",
  265. "69":"y",
  266. "70":"y",
  267. "71":"y",
  268. "72":"y",
  269. "73":"y",
  270. "74":"y",
  271. "75":"y",
  272. "76":"y",
  273. "77":"y",
  274. "78":"y",
  275. "79":"y",
  276. "80":"y",
  277. "81":"y",
  278. "83":"y",
  279. "84":"y",
  280. "85":"y",
  281. "86":"y",
  282. "87":"y",
  283. "88":"y",
  284. "89":"y",
  285. "90":"y",
  286. "91":"y",
  287. "92":"y",
  288. "93":"y",
  289. "94":"y",
  290. "95":"y",
  291. "96":"y",
  292. "97":"y",
  293. "98":"y",
  294. "99":"y",
  295. "100":"y",
  296. "101":"y",
  297. "102":"y",
  298. "103":"y",
  299. "104":"y",
  300. "105":"y",
  301. "106":"y",
  302. "107":"y",
  303. "108":"y",
  304. "109":"y",
  305. "110":"y",
  306. "111":"y",
  307. "112":"y",
  308. "113":"y"
  309. },
  310. "safari":{
  311. "3.1":"n",
  312. "3.2":"n",
  313. "4":"n",
  314. "5":"n",
  315. "5.1":"a #2",
  316. "6":"y #2",
  317. "6.1":"y #2",
  318. "7":"y",
  319. "7.1":"y",
  320. "8":"y",
  321. "9":"y",
  322. "9.1":"y",
  323. "10":"y",
  324. "10.1":"y",
  325. "11":"y",
  326. "11.1":"y",
  327. "12":"y",
  328. "12.1":"y",
  329. "13":"y",
  330. "13.1":"y",
  331. "14":"y",
  332. "14.1":"y",
  333. "15":"y",
  334. "15.1":"y",
  335. "15.2-15.3":"y",
  336. "15.4":"y",
  337. "15.5":"y",
  338. "15.6":"y",
  339. "16.0":"y",
  340. "16.1":"y",
  341. "16.2":"y",
  342. "16.3":"y",
  343. "16.4":"y",
  344. "TP":"y"
  345. },
  346. "opera":{
  347. "9":"n",
  348. "9.5-9.6":"n",
  349. "10.0-10.1":"n",
  350. "10.5":"n",
  351. "10.6":"n",
  352. "11":"n",
  353. "11.1":"n",
  354. "11.5":"n",
  355. "11.6":"n",
  356. "12":"n",
  357. "12.1":"n",
  358. "15":"y",
  359. "16":"y",
  360. "17":"y",
  361. "18":"y",
  362. "19":"y",
  363. "20":"y",
  364. "21":"y",
  365. "22":"y",
  366. "23":"y",
  367. "24":"y",
  368. "25":"y",
  369. "26":"y",
  370. "27":"y",
  371. "28":"y",
  372. "29":"y",
  373. "30":"y",
  374. "31":"y",
  375. "32":"y",
  376. "33":"y",
  377. "34":"y",
  378. "35":"y",
  379. "36":"y",
  380. "37":"y",
  381. "38":"y",
  382. "39":"y",
  383. "40":"y",
  384. "41":"y",
  385. "42":"y",
  386. "43":"y",
  387. "44":"y",
  388. "45":"y",
  389. "46":"y",
  390. "47":"y",
  391. "48":"y",
  392. "49":"y",
  393. "50":"y",
  394. "51":"y",
  395. "52":"y",
  396. "53":"y",
  397. "54":"y",
  398. "55":"y",
  399. "56":"y",
  400. "57":"y",
  401. "58":"y",
  402. "60":"y",
  403. "62":"y",
  404. "63":"y",
  405. "64":"y",
  406. "65":"y",
  407. "66":"y",
  408. "67":"y",
  409. "68":"y",
  410. "69":"y",
  411. "70":"y",
  412. "71":"y",
  413. "72":"y",
  414. "73":"y",
  415. "74":"y",
  416. "75":"y",
  417. "76":"y",
  418. "77":"y",
  419. "78":"y",
  420. "79":"y",
  421. "80":"y",
  422. "81":"y",
  423. "82":"y",
  424. "83":"y",
  425. "84":"y",
  426. "85":"y",
  427. "86":"y",
  428. "87":"y",
  429. "88":"y",
  430. "89":"y",
  431. "90":"y",
  432. "91":"y",
  433. "92":"y",
  434. "93":"y",
  435. "94":"y",
  436. "95":"y"
  437. },
  438. "ios_saf":{
  439. "3.2":"n",
  440. "4.0-4.1":"n",
  441. "4.2-4.3":"n",
  442. "5.0-5.1":"a #2",
  443. "6.0-6.1":"y #2",
  444. "7.0-7.1":"y",
  445. "8":"y",
  446. "8.1-8.4":"y",
  447. "9.0-9.2":"y",
  448. "9.3":"y",
  449. "10.0-10.2":"y",
  450. "10.3":"y",
  451. "11.0-11.2":"y",
  452. "11.3-11.4":"y",
  453. "12.0-12.1":"y",
  454. "12.2-12.5":"y",
  455. "13.0-13.1":"y",
  456. "13.2":"y",
  457. "13.3":"y",
  458. "13.4-13.7":"y",
  459. "14.0-14.4":"y",
  460. "14.5-14.8":"y",
  461. "15.0-15.1":"y",
  462. "15.2-15.3":"y",
  463. "15.4":"y",
  464. "15.5":"y",
  465. "15.6":"y",
  466. "16.0":"y",
  467. "16.1":"y",
  468. "16.2":"y",
  469. "16.3":"y",
  470. "16.4":"y"
  471. },
  472. "op_mini":{
  473. "all":"n"
  474. },
  475. "android":{
  476. "2.1":"n",
  477. "2.2":"n",
  478. "2.3":"n",
  479. "3":"n",
  480. "4":"n",
  481. "4.1":"n",
  482. "4.2-4.3":"n",
  483. "4.4":"y",
  484. "4.4.3-4.4.4":"y",
  485. "109":"y"
  486. },
  487. "bb":{
  488. "7":"n",
  489. "10":"y #2"
  490. },
  491. "op_mob":{
  492. "10":"n",
  493. "11":"n",
  494. "11.1":"n",
  495. "11.5":"n",
  496. "12":"n",
  497. "12.1":"n",
  498. "73":"y"
  499. },
  500. "and_chr":{
  501. "110":"y"
  502. },
  503. "and_ff":{
  504. "110":"y"
  505. },
  506. "ie_mob":{
  507. "10":"a #1",
  508. "11":"a #1"
  509. },
  510. "and_uc":{
  511. "13.4":"y"
  512. },
  513. "samsung":{
  514. "4":"y",
  515. "5.0-5.4":"y",
  516. "6.2-6.4":"y",
  517. "7.2-7.4":"y",
  518. "8.2":"y",
  519. "9.2":"y",
  520. "10.1":"y",
  521. "11.1-11.2":"y",
  522. "12.0":"y",
  523. "13.0":"y",
  524. "14.0":"y",
  525. "15.0":"y",
  526. "16.0":"y",
  527. "17.0":"y",
  528. "18.0":"y",
  529. "19.0":"y",
  530. "20":"y"
  531. },
  532. "and_qq":{
  533. "13.1":"y"
  534. },
  535. "baidu":{
  536. "13.18":"y"
  537. },
  538. "kaios":{
  539. "2.5":"y",
  540. "3.0-3.1":"y"
  541. }
  542. },
  543. "notes":"The standard HTTP header is `Content-Security-Policy` which is used unless otherwise noted.",
  544. "notes_by_num":{
  545. "1":"Supported through the `X-Content-Security-Policy` header",
  546. "2":"Supported through the `X-WebKit-CSP` header"
  547. },
  548. "usage_perc_y":97.27,
  549. "usage_perc_a":0.54,
  550. "ucprefix":false,
  551. "parent":"",
  552. "keywords":"csp,security,header",
  553. "ie_id":"contentsecuritypolicy",
  554. "chrome_id":"5205088045891584",
  555. "firefox_id":"",
  556. "webkit_id":"",
  557. "shown":true
  558. }