contentsecuritypolicy.json 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357
  1. {
  2. "title":"Content Security Policy 1.0",
  3. "description":"Mitigate cross-site scripting attacks by whitelisting allowed sources of script, style, and other resources.",
  4. "spec":"https://www.w3.org/TR/2012/CR-CSP-20121115/",
  5. "status":"cr",
  6. "links":[
  7. {
  8. "url":"https://www.html5rocks.com/en/tutorials/security/content-security-policy/",
  9. "title":"HTML5Rocks article"
  10. },
  11. {
  12. "url":"http://content-security-policy.com/",
  13. "title":"CSP Examples & Quick Reference"
  14. },
  15. {
  16. "url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP",
  17. "title":"MDN Web Docs - Content Security Policy"
  18. }
  19. ],
  20. "bugs":[
  21. {
  22. "description":"Partial support in Internet Explorer 10-11 refers to the browser only supporting the 'sandbox' directive by using the `X-Content-Security-Policy` header."
  23. },
  24. {
  25. "description":"Partial support in iOS Safari 5.0-5.1 refers to the browser recognizing the `X-WebKit-CSP` header but failing to handle complex cases correctly, often resulting in broken pages."
  26. },
  27. {
  28. "description":"Chrome for iOS fails to render pages without a [connect-src 'self'](https://code.google.com/p/chromium/issues/detail?id=322497) policy."
  29. }
  30. ],
  31. "categories":[
  32. "Security"
  33. ],
  34. "stats":{
  35. "ie":{
  36. "5.5":"n",
  37. "6":"n",
  38. "7":"n",
  39. "8":"n",
  40. "9":"n",
  41. "10":"a #1",
  42. "11":"a #1"
  43. },
  44. "edge":{
  45. "12":"y",
  46. "13":"y",
  47. "14":"y",
  48. "15":"y",
  49. "16":"y",
  50. "17":"y",
  51. "18":"y"
  52. },
  53. "firefox":{
  54. "2":"n",
  55. "3":"n",
  56. "3.5":"n",
  57. "3.6":"n",
  58. "4":"y #1",
  59. "5":"y #1",
  60. "6":"y #1",
  61. "7":"y #1",
  62. "8":"y #1",
  63. "9":"y #1",
  64. "10":"y #1",
  65. "11":"y #1",
  66. "12":"y #1",
  67. "13":"y #1",
  68. "14":"y #1",
  69. "15":"y #1",
  70. "16":"y #1",
  71. "17":"y #1",
  72. "18":"y #1",
  73. "19":"y #1",
  74. "20":"y #1",
  75. "21":"y #1",
  76. "22":"y #1",
  77. "23":"y",
  78. "24":"y",
  79. "25":"y",
  80. "26":"y",
  81. "27":"y",
  82. "28":"y",
  83. "29":"y",
  84. "30":"y",
  85. "31":"y",
  86. "32":"y",
  87. "33":"y",
  88. "34":"y",
  89. "35":"y",
  90. "36":"y",
  91. "37":"y",
  92. "38":"y",
  93. "39":"y",
  94. "40":"y",
  95. "41":"y",
  96. "42":"y",
  97. "43":"y",
  98. "44":"y",
  99. "45":"y",
  100. "46":"y",
  101. "47":"y",
  102. "48":"y",
  103. "49":"y",
  104. "50":"y",
  105. "51":"y",
  106. "52":"y",
  107. "53":"y",
  108. "54":"y",
  109. "55":"y",
  110. "56":"y",
  111. "57":"y",
  112. "58":"y",
  113. "59":"y",
  114. "60":"y",
  115. "61":"y",
  116. "62":"y",
  117. "63":"y",
  118. "64":"y",
  119. "65":"y",
  120. "66":"y"
  121. },
  122. "chrome":{
  123. "4":"n",
  124. "5":"n",
  125. "6":"n",
  126. "7":"n",
  127. "8":"n",
  128. "9":"n",
  129. "10":"n",
  130. "11":"n",
  131. "12":"n",
  132. "13":"n",
  133. "14":"y #2",
  134. "15":"y #2",
  135. "16":"y #2",
  136. "17":"y #2",
  137. "18":"y #2",
  138. "19":"y #2",
  139. "20":"y #2",
  140. "21":"y #2",
  141. "22":"y #2",
  142. "23":"y #2",
  143. "24":"y #2",
  144. "25":"y",
  145. "26":"y",
  146. "27":"y",
  147. "28":"y",
  148. "29":"y",
  149. "30":"y",
  150. "31":"y",
  151. "32":"y",
  152. "33":"y",
  153. "34":"y",
  154. "35":"y",
  155. "36":"y",
  156. "37":"y",
  157. "38":"y",
  158. "39":"y",
  159. "40":"y",
  160. "41":"y",
  161. "42":"y",
  162. "43":"y",
  163. "44":"y",
  164. "45":"y",
  165. "46":"y",
  166. "47":"y",
  167. "48":"y",
  168. "49":"y",
  169. "50":"y",
  170. "51":"y",
  171. "52":"y",
  172. "53":"y",
  173. "54":"y",
  174. "55":"y",
  175. "56":"y",
  176. "57":"y",
  177. "58":"y",
  178. "59":"y",
  179. "60":"y",
  180. "61":"y",
  181. "62":"y",
  182. "63":"y",
  183. "64":"y",
  184. "65":"y",
  185. "66":"y",
  186. "67":"y",
  187. "68":"y",
  188. "69":"y",
  189. "70":"y",
  190. "71":"y",
  191. "72":"y",
  192. "73":"y",
  193. "74":"y"
  194. },
  195. "safari":{
  196. "3.1":"n",
  197. "3.2":"n",
  198. "4":"n",
  199. "5":"n",
  200. "5.1":"a #2",
  201. "6":"y #2",
  202. "6.1":"y #2",
  203. "7":"y",
  204. "7.1":"y",
  205. "8":"y",
  206. "9":"y",
  207. "9.1":"y",
  208. "10":"y",
  209. "10.1":"y",
  210. "11":"y",
  211. "11.1":"y",
  212. "12":"y",
  213. "TP":"y"
  214. },
  215. "opera":{
  216. "9":"n",
  217. "9.5-9.6":"n",
  218. "10.0-10.1":"n",
  219. "10.5":"n",
  220. "10.6":"n",
  221. "11":"n",
  222. "11.1":"n",
  223. "11.5":"n",
  224. "11.6":"n",
  225. "12":"n",
  226. "12.1":"n",
  227. "15":"y",
  228. "16":"y",
  229. "17":"y",
  230. "18":"y",
  231. "19":"y",
  232. "20":"y",
  233. "21":"y",
  234. "22":"y",
  235. "23":"y",
  236. "24":"y",
  237. "25":"y",
  238. "26":"y",
  239. "27":"y",
  240. "28":"y",
  241. "29":"y",
  242. "30":"y",
  243. "31":"y",
  244. "32":"y",
  245. "33":"y",
  246. "34":"y",
  247. "35":"y",
  248. "36":"y",
  249. "37":"y",
  250. "38":"y",
  251. "39":"y",
  252. "40":"y",
  253. "41":"y",
  254. "42":"y",
  255. "43":"y",
  256. "44":"y",
  257. "45":"y",
  258. "46":"y",
  259. "47":"y",
  260. "48":"y",
  261. "49":"y",
  262. "50":"y",
  263. "51":"y",
  264. "52":"y",
  265. "53":"y",
  266. "54":"y",
  267. "55":"y",
  268. "56":"y",
  269. "57":"y"
  270. },
  271. "ios_saf":{
  272. "3.2":"n",
  273. "4.0-4.1":"n",
  274. "4.2-4.3":"n",
  275. "5.0-5.1":"a #2",
  276. "6.0-6.1":"y #2",
  277. "7.0-7.1":"y",
  278. "8":"y",
  279. "8.1-8.4":"y",
  280. "9.0-9.2":"y",
  281. "9.3":"y",
  282. "10.0-10.2":"y",
  283. "10.3":"y",
  284. "11.0-11.2":"y",
  285. "11.3-11.4":"y",
  286. "12.0-12.1":"y"
  287. },
  288. "op_mini":{
  289. "all":"n"
  290. },
  291. "android":{
  292. "2.1":"n",
  293. "2.2":"n",
  294. "2.3":"n",
  295. "3":"n",
  296. "4":"n",
  297. "4.1":"n",
  298. "4.2-4.3":"n",
  299. "4.4":"y",
  300. "4.4.3-4.4.4":"y",
  301. "67":"y"
  302. },
  303. "bb":{
  304. "7":"n",
  305. "10":"y #2"
  306. },
  307. "op_mob":{
  308. "10":"n",
  309. "11":"n",
  310. "11.1":"n",
  311. "11.5":"n",
  312. "12":"n",
  313. "12.1":"n",
  314. "46":"y"
  315. },
  316. "and_chr":{
  317. "70":"y"
  318. },
  319. "and_ff":{
  320. "63":"y"
  321. },
  322. "ie_mob":{
  323. "10":"a #1",
  324. "11":"a #1"
  325. },
  326. "and_uc":{
  327. "11.8":"y #2"
  328. },
  329. "samsung":{
  330. "4":"y",
  331. "5":"y",
  332. "6.2":"y",
  333. "7.2":"y"
  334. },
  335. "and_qq":{
  336. "1.2":"y"
  337. },
  338. "baidu":{
  339. "7.12":"y"
  340. }
  341. },
  342. "notes":"The standard HTTP header is `Content-Security-Policy` which is used unless otherwise noted.",
  343. "notes_by_num":{
  344. "1":"Supported through the `X-Content-Security-Policy` header",
  345. "2":"Supported through the `X-WebKit-CSP` header"
  346. },
  347. "usage_perc_y":90.18,
  348. "usage_perc_a":2.74,
  349. "ucprefix":false,
  350. "parent":"",
  351. "keywords":"csp,security,header",
  352. "ie_id":"contentsecuritypolicy",
  353. "chrome_id":"5205088045891584",
  354. "firefox_id":"",
  355. "webkit_id":"",
  356. "shown":true
  357. }