contentsecuritypolicy.json 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320
  1. {
  2. "title":"Content Security Policy 1.0",
  3. "description":"Mitigate cross-site scripting attacks by whitelisting allowed sources of script, style, and other resources.",
  4. "spec":"http://www.w3.org/TR/2012/CR-CSP-20121115/",
  5. "status":"cr",
  6. "links":[
  7. {
  8. "url":"http://html5rocks.com/en/tutorials/security/content-security-policy/",
  9. "title":"HTML5Rocks article"
  10. },
  11. {
  12. "url":"http://content-security-policy.com/",
  13. "title":"CSP Examples & Quick Reference"
  14. },
  15. {
  16. "url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP",
  17. "title":"Mozilla Developer Network (MDN) documentation - Content Security Policy"
  18. }
  19. ],
  20. "bugs":[
  21. {
  22. "description":"Partial support in Internet Explorer 10-11 refers to the browser only supporting the 'sandbox' directive by using the `X-Content-Security-Policy` header."
  23. },
  24. {
  25. "description":"Partial support in iOS Safari 5.0-5.1 refers to the browser recognizing the `X-Webkit-CSP` header but failing to handle complex cases correctly, often resulting in broken pages."
  26. },
  27. {
  28. "description":"Chrome for iOS fails to render pages without a [connect-src 'self'](https://code.google.com/p/chromium/issues/detail?id=322497) policy."
  29. }
  30. ],
  31. "categories":[
  32. "Security"
  33. ],
  34. "stats":{
  35. "ie":{
  36. "5.5":"n",
  37. "6":"n",
  38. "7":"n",
  39. "8":"n",
  40. "9":"n",
  41. "10":"a #1",
  42. "11":"a #1"
  43. },
  44. "edge":{
  45. "12":"y",
  46. "13":"y",
  47. "14":"y",
  48. "15":"y",
  49. "16":"y"
  50. },
  51. "firefox":{
  52. "2":"n",
  53. "3":"n",
  54. "3.5":"n",
  55. "3.6":"n",
  56. "4":"y #1",
  57. "5":"y #1",
  58. "6":"y #1",
  59. "7":"y #1",
  60. "8":"y #1",
  61. "9":"y #1",
  62. "10":"y #1",
  63. "11":"y #1",
  64. "12":"y #1",
  65. "13":"y #1",
  66. "14":"y #1",
  67. "15":"y #1",
  68. "16":"y #1",
  69. "17":"y #1",
  70. "18":"y #1",
  71. "19":"y #1",
  72. "20":"y #1",
  73. "21":"y #1",
  74. "22":"y #1",
  75. "23":"y",
  76. "24":"y",
  77. "25":"y",
  78. "26":"y",
  79. "27":"y",
  80. "28":"y",
  81. "29":"y",
  82. "30":"y",
  83. "31":"y",
  84. "32":"y",
  85. "33":"y",
  86. "34":"y",
  87. "35":"y",
  88. "36":"y",
  89. "37":"y",
  90. "38":"y",
  91. "39":"y",
  92. "40":"y",
  93. "41":"y",
  94. "42":"y",
  95. "43":"y",
  96. "44":"y",
  97. "45":"y",
  98. "46":"y",
  99. "47":"y",
  100. "48":"y",
  101. "49":"y",
  102. "50":"y",
  103. "51":"y",
  104. "52":"y",
  105. "53":"y",
  106. "54":"y",
  107. "55":"y",
  108. "56":"y",
  109. "57":"y"
  110. },
  111. "chrome":{
  112. "4":"n",
  113. "5":"n",
  114. "6":"n",
  115. "7":"n",
  116. "8":"n",
  117. "9":"n",
  118. "10":"n",
  119. "11":"n",
  120. "12":"n",
  121. "13":"n",
  122. "14":"y #2",
  123. "15":"y #2",
  124. "16":"y #2",
  125. "17":"y #2",
  126. "18":"y #2",
  127. "19":"y #2",
  128. "20":"y #2",
  129. "21":"y #2",
  130. "22":"y #2",
  131. "23":"y #2",
  132. "24":"y #2",
  133. "25":"y",
  134. "26":"y",
  135. "27":"y",
  136. "28":"y",
  137. "29":"y",
  138. "30":"y",
  139. "31":"y",
  140. "32":"y",
  141. "33":"y",
  142. "34":"y",
  143. "35":"y",
  144. "36":"y",
  145. "37":"y",
  146. "38":"y",
  147. "39":"y",
  148. "40":"y",
  149. "41":"y",
  150. "42":"y",
  151. "43":"y",
  152. "44":"y",
  153. "45":"y",
  154. "46":"y",
  155. "47":"y",
  156. "48":"y",
  157. "49":"y",
  158. "50":"y",
  159. "51":"y",
  160. "52":"y",
  161. "53":"y",
  162. "54":"y",
  163. "55":"y",
  164. "56":"y",
  165. "57":"y",
  166. "58":"y",
  167. "59":"y",
  168. "60":"y",
  169. "61":"y",
  170. "62":"y",
  171. "63":"y"
  172. },
  173. "safari":{
  174. "3.1":"n",
  175. "3.2":"n",
  176. "4":"n",
  177. "5":"n",
  178. "5.1":"a #2",
  179. "6":"y #2",
  180. "6.1":"y #2",
  181. "7":"y",
  182. "7.1":"y",
  183. "8":"y",
  184. "9":"y",
  185. "9.1":"y",
  186. "10":"y",
  187. "10.1":"y",
  188. "11":"y",
  189. "TP":"y"
  190. },
  191. "opera":{
  192. "9":"n",
  193. "9.5-9.6":"n",
  194. "10.0-10.1":"n",
  195. "10.5":"n",
  196. "10.6":"n",
  197. "11":"n",
  198. "11.1":"n",
  199. "11.5":"n",
  200. "11.6":"n",
  201. "12":"n",
  202. "12.1":"n",
  203. "15":"y",
  204. "16":"y",
  205. "17":"y",
  206. "18":"y",
  207. "19":"y",
  208. "20":"y",
  209. "21":"y",
  210. "22":"y",
  211. "23":"y",
  212. "24":"y",
  213. "25":"y",
  214. "26":"y",
  215. "27":"y",
  216. "28":"y",
  217. "29":"y",
  218. "30":"y",
  219. "31":"y",
  220. "32":"y",
  221. "33":"y",
  222. "34":"y",
  223. "35":"y",
  224. "36":"y",
  225. "37":"y",
  226. "38":"y",
  227. "39":"y",
  228. "40":"y",
  229. "41":"y",
  230. "42":"y",
  231. "43":"y",
  232. "44":"y",
  233. "45":"y",
  234. "46":"y",
  235. "47":"y",
  236. "48":"y"
  237. },
  238. "ios_saf":{
  239. "3.2":"n",
  240. "4.0-4.1":"n",
  241. "4.2-4.3":"n",
  242. "5.0-5.1":"a #2",
  243. "6.0-6.1":"y #2",
  244. "7.0-7.1":"y",
  245. "8":"y",
  246. "8.1-8.4":"y",
  247. "9.0-9.2":"y",
  248. "9.3":"y",
  249. "10.0-10.2":"y",
  250. "10.3":"y",
  251. "11":"y"
  252. },
  253. "op_mini":{
  254. "all":"n"
  255. },
  256. "android":{
  257. "2.1":"n",
  258. "2.2":"n",
  259. "2.3":"n",
  260. "3":"n",
  261. "4":"n",
  262. "4.1":"n",
  263. "4.2-4.3":"n",
  264. "4.4":"y",
  265. "4.4.3-4.4.4":"y",
  266. "56":"y"
  267. },
  268. "bb":{
  269. "7":"n",
  270. "10":"y #2"
  271. },
  272. "op_mob":{
  273. "10":"n",
  274. "11":"n",
  275. "11.1":"n",
  276. "11.5":"n",
  277. "12":"n",
  278. "12.1":"n",
  279. "37":"y"
  280. },
  281. "and_chr":{
  282. "59":"y"
  283. },
  284. "and_ff":{
  285. "54":"y"
  286. },
  287. "ie_mob":{
  288. "10":"a #1",
  289. "11":"a #1"
  290. },
  291. "and_uc":{
  292. "11.4":"y #2"
  293. },
  294. "samsung":{
  295. "4":"y",
  296. "5":"y"
  297. },
  298. "and_qq":{
  299. "1.2":"y"
  300. },
  301. "baidu":{
  302. "7.12":"y"
  303. }
  304. },
  305. "notes":"The standard HTTP header is `Content-Security-Policy` which is used unless otherwise noted.",
  306. "notes_by_num":{
  307. "1":"Supported through the `X-Content-Security-Policy` header",
  308. "2":"Supported through the `X-Webkit-CSP` header"
  309. },
  310. "usage_perc_y":89.48,
  311. "usage_perc_a":3.72,
  312. "ucprefix":false,
  313. "parent":"",
  314. "keywords":"csp,security,header",
  315. "ie_id":"contentsecuritypolicy",
  316. "chrome_id":"5205088045891584",
  317. "firefox_id":"",
  318. "webkit_id":"",
  319. "shown":true
  320. }