contentsecuritypolicy.json 5.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288
  1. {
  2. "title":"Content Security Policy 1.0",
  3. "description":"Mitigate cross-site scripting attacks by whitelisting allowed sources of script, style, and other resources.",
  4. "spec":"http://www.w3.org/TR/2012/CR-CSP-20121115/",
  5. "status":"cr",
  6. "links":[
  7. {
  8. "url":"http://html5rocks.com/en/tutorials/security/content-security-policy/",
  9. "title":"HTML5Rocks article"
  10. },
  11. {
  12. "url":"http://content-security-policy.com/",
  13. "title":"CSP Examples & Quick Reference"
  14. }
  15. ],
  16. "bugs":[
  17. {
  18. "description":"Partial support in Internet Explorer 10-11 refers to the browser only supporting the 'sandbox' directive by using the `X-Content-Security-Policy` header."
  19. },
  20. {
  21. "description":"Partial support in iOS Safari 5.0-5.1 refers to the browser recognizing the `X-Webkit-CSP` header but failing to handle complex cases correctly, often resulting in broken pages."
  22. },
  23. {
  24. "description":"Chrome for iOS fails to render pages without a [connect-src 'self'](https://code.google.com/p/chromium/issues/detail?id=322497) policy."
  25. }
  26. ],
  27. "categories":[
  28. "Other"
  29. ],
  30. "stats":{
  31. "ie":{
  32. "5.5":"n",
  33. "6":"n",
  34. "7":"n",
  35. "8":"n",
  36. "9":"n",
  37. "10":"a #1",
  38. "11":"a #1"
  39. },
  40. "edge":{
  41. "12":"y",
  42. "13":"y",
  43. "14":"y"
  44. },
  45. "firefox":{
  46. "2":"n",
  47. "3":"n",
  48. "3.5":"n",
  49. "3.6":"n",
  50. "4":"y #1",
  51. "5":"y #1",
  52. "6":"y #1",
  53. "7":"y #1",
  54. "8":"y #1",
  55. "9":"y #1",
  56. "10":"y #1",
  57. "11":"y #1",
  58. "12":"y #1",
  59. "13":"y #1",
  60. "14":"y #1",
  61. "15":"y #1",
  62. "16":"y #1",
  63. "17":"y #1",
  64. "18":"y #1",
  65. "19":"y #1",
  66. "20":"y #1",
  67. "21":"y #1",
  68. "22":"y #1",
  69. "23":"y",
  70. "24":"y",
  71. "25":"y",
  72. "26":"y",
  73. "27":"y",
  74. "28":"y",
  75. "29":"y",
  76. "30":"y",
  77. "31":"y",
  78. "32":"y",
  79. "33":"y",
  80. "34":"y",
  81. "35":"y",
  82. "36":"y",
  83. "37":"y",
  84. "38":"y",
  85. "39":"y",
  86. "40":"y",
  87. "41":"y",
  88. "42":"y",
  89. "43":"y",
  90. "44":"y",
  91. "45":"y",
  92. "46":"y",
  93. "47":"y",
  94. "48":"y",
  95. "49":"y",
  96. "50":"y",
  97. "51":"y",
  98. "52":"y",
  99. "53":"y"
  100. },
  101. "chrome":{
  102. "4":"n",
  103. "5":"n",
  104. "6":"n",
  105. "7":"n",
  106. "8":"n",
  107. "9":"n",
  108. "10":"n",
  109. "11":"n",
  110. "12":"n",
  111. "13":"n",
  112. "14":"y #2",
  113. "15":"y #2",
  114. "16":"y #2",
  115. "17":"y #2",
  116. "18":"y #2",
  117. "19":"y #2",
  118. "20":"y #2",
  119. "21":"y #2",
  120. "22":"y #2",
  121. "23":"y #2",
  122. "24":"y #2",
  123. "25":"y",
  124. "26":"y",
  125. "27":"y",
  126. "28":"y",
  127. "29":"y",
  128. "30":"y",
  129. "31":"y",
  130. "32":"y",
  131. "33":"y",
  132. "34":"y",
  133. "35":"y",
  134. "36":"y",
  135. "37":"y",
  136. "38":"y",
  137. "39":"y",
  138. "40":"y",
  139. "41":"y",
  140. "42":"y",
  141. "43":"y",
  142. "44":"y",
  143. "45":"y",
  144. "46":"y",
  145. "47":"y",
  146. "48":"y",
  147. "49":"y",
  148. "50":"y",
  149. "51":"y",
  150. "52":"y",
  151. "53":"y",
  152. "54":"y",
  153. "55":"y",
  154. "56":"y",
  155. "57":"y"
  156. },
  157. "safari":{
  158. "3.1":"n",
  159. "3.2":"n",
  160. "4":"n",
  161. "5":"n",
  162. "5.1":"a #2",
  163. "6":"y #2",
  164. "6.1":"y #2",
  165. "7":"y",
  166. "7.1":"y",
  167. "8":"y",
  168. "9":"y",
  169. "9.1":"y",
  170. "10":"y",
  171. "TP":"y"
  172. },
  173. "opera":{
  174. "9":"n",
  175. "9.5-9.6":"n",
  176. "10.0-10.1":"n",
  177. "10.5":"n",
  178. "10.6":"n",
  179. "11":"n",
  180. "11.1":"n",
  181. "11.5":"n",
  182. "11.6":"n",
  183. "12":"n",
  184. "12.1":"n",
  185. "15":"y",
  186. "16":"y",
  187. "17":"y",
  188. "18":"y",
  189. "19":"y",
  190. "20":"y",
  191. "21":"y",
  192. "22":"y",
  193. "23":"y",
  194. "24":"y",
  195. "25":"y",
  196. "26":"y",
  197. "27":"y",
  198. "28":"y",
  199. "29":"y",
  200. "30":"y",
  201. "31":"y",
  202. "32":"y",
  203. "33":"y",
  204. "34":"y",
  205. "35":"y",
  206. "36":"y",
  207. "37":"y",
  208. "38":"y",
  209. "39":"y",
  210. "40":"y",
  211. "41":"y",
  212. "42":"y",
  213. "43":"y"
  214. },
  215. "ios_saf":{
  216. "3.2":"n",
  217. "4.0-4.1":"n",
  218. "4.2-4.3":"n",
  219. "5.0-5.1":"a #2",
  220. "6.0-6.1":"y #2",
  221. "7.0-7.1":"y",
  222. "8":"y",
  223. "8.1-8.4":"y",
  224. "9.0-9.2":"y",
  225. "9.3":"y",
  226. "10-10.1":"y"
  227. },
  228. "op_mini":{
  229. "all":"n"
  230. },
  231. "android":{
  232. "2.1":"n",
  233. "2.2":"n",
  234. "2.3":"n",
  235. "3":"n",
  236. "4":"n",
  237. "4.1":"n",
  238. "4.2-4.3":"n",
  239. "4.4":"y",
  240. "4.4.3-4.4.4":"y",
  241. "53":"y"
  242. },
  243. "bb":{
  244. "7":"n",
  245. "10":"y #2"
  246. },
  247. "op_mob":{
  248. "10":"n",
  249. "11":"n",
  250. "11.1":"n",
  251. "11.5":"n",
  252. "12":"n",
  253. "12.1":"n",
  254. "37":"y"
  255. },
  256. "and_chr":{
  257. "54":"y"
  258. },
  259. "and_ff":{
  260. "50":"y"
  261. },
  262. "ie_mob":{
  263. "10":"a #1",
  264. "11":"a #1"
  265. },
  266. "and_uc":{
  267. "11":"y #2"
  268. },
  269. "samsung":{
  270. "4":"y"
  271. }
  272. },
  273. "notes":"The standard HTTP header is `Content-Security-Policy` which is used unless otherwise noted.",
  274. "notes_by_num":{
  275. "1":"Supported through the `X-Content-Security-Policy` header",
  276. "2":"Supported through the `X-Webkit-CSP` header"
  277. },
  278. "usage_perc_y":87.47,
  279. "usage_perc_a":4.56,
  280. "ucprefix":false,
  281. "parent":"",
  282. "keywords":"csp,security,header",
  283. "ie_id":"contentsecuritypolicy",
  284. "chrome_id":"5205088045891584",
  285. "firefox_id":"",
  286. "webkit_id":"",
  287. "shown":true
  288. }