contentsecuritypolicy.json 5.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291
  1. {
  2. "title":"Content Security Policy 1.0",
  3. "description":"Mitigate cross-site scripting attacks by whitelisting allowed sources of script, style, and other resources.",
  4. "spec":"http://www.w3.org/TR/2012/CR-CSP-20121115/",
  5. "status":"cr",
  6. "links":[
  7. {
  8. "url":"http://html5rocks.com/en/tutorials/security/content-security-policy/",
  9. "title":"HTML5Rocks article"
  10. },
  11. {
  12. "url":"http://content-security-policy.com/",
  13. "title":"CSP Examples & Quick Reference"
  14. }
  15. ],
  16. "bugs":[
  17. {
  18. "description":"Partial support in Internet Explorer 10-11 refers to the browser only supporting the 'sandbox' directive by using the `X-Content-Security-Policy` header."
  19. },
  20. {
  21. "description":"Partial support in iOS Safari 5.0-5.1 refers to the browser recognizing the `X-Webkit-CSP` header but failing to handle complex cases correctly, often resulting in broken pages."
  22. },
  23. {
  24. "description":"Chrome for iOS fails to render pages without a [connect-src 'self'](https://code.google.com/p/chromium/issues/detail?id=322497) policy."
  25. }
  26. ],
  27. "categories":[
  28. "Other"
  29. ],
  30. "stats":{
  31. "ie":{
  32. "5.5":"n",
  33. "6":"n",
  34. "7":"n",
  35. "8":"n",
  36. "9":"n",
  37. "10":"a #1",
  38. "11":"a #1"
  39. },
  40. "edge":{
  41. "12":"y",
  42. "13":"y",
  43. "14":"y",
  44. "15":"y"
  45. },
  46. "firefox":{
  47. "2":"n",
  48. "3":"n",
  49. "3.5":"n",
  50. "3.6":"n",
  51. "4":"y #1",
  52. "5":"y #1",
  53. "6":"y #1",
  54. "7":"y #1",
  55. "8":"y #1",
  56. "9":"y #1",
  57. "10":"y #1",
  58. "11":"y #1",
  59. "12":"y #1",
  60. "13":"y #1",
  61. "14":"y #1",
  62. "15":"y #1",
  63. "16":"y #1",
  64. "17":"y #1",
  65. "18":"y #1",
  66. "19":"y #1",
  67. "20":"y #1",
  68. "21":"y #1",
  69. "22":"y #1",
  70. "23":"y",
  71. "24":"y",
  72. "25":"y",
  73. "26":"y",
  74. "27":"y",
  75. "28":"y",
  76. "29":"y",
  77. "30":"y",
  78. "31":"y",
  79. "32":"y",
  80. "33":"y",
  81. "34":"y",
  82. "35":"y",
  83. "36":"y",
  84. "37":"y",
  85. "38":"y",
  86. "39":"y",
  87. "40":"y",
  88. "41":"y",
  89. "42":"y",
  90. "43":"y",
  91. "44":"y",
  92. "45":"y",
  93. "46":"y",
  94. "47":"y",
  95. "48":"y",
  96. "49":"y",
  97. "50":"y",
  98. "51":"y",
  99. "52":"y",
  100. "53":"y"
  101. },
  102. "chrome":{
  103. "4":"n",
  104. "5":"n",
  105. "6":"n",
  106. "7":"n",
  107. "8":"n",
  108. "9":"n",
  109. "10":"n",
  110. "11":"n",
  111. "12":"n",
  112. "13":"n",
  113. "14":"y #2",
  114. "15":"y #2",
  115. "16":"y #2",
  116. "17":"y #2",
  117. "18":"y #2",
  118. "19":"y #2",
  119. "20":"y #2",
  120. "21":"y #2",
  121. "22":"y #2",
  122. "23":"y #2",
  123. "24":"y #2",
  124. "25":"y",
  125. "26":"y",
  126. "27":"y",
  127. "28":"y",
  128. "29":"y",
  129. "30":"y",
  130. "31":"y",
  131. "32":"y",
  132. "33":"y",
  133. "34":"y",
  134. "35":"y",
  135. "36":"y",
  136. "37":"y",
  137. "38":"y",
  138. "39":"y",
  139. "40":"y",
  140. "41":"y",
  141. "42":"y",
  142. "43":"y",
  143. "44":"y",
  144. "45":"y",
  145. "46":"y",
  146. "47":"y",
  147. "48":"y",
  148. "49":"y",
  149. "50":"y",
  150. "51":"y",
  151. "52":"y",
  152. "53":"y",
  153. "54":"y",
  154. "55":"y",
  155. "56":"y",
  156. "57":"y",
  157. "58":"y"
  158. },
  159. "safari":{
  160. "3.1":"n",
  161. "3.2":"n",
  162. "4":"n",
  163. "5":"n",
  164. "5.1":"a #2",
  165. "6":"y #2",
  166. "6.1":"y #2",
  167. "7":"y",
  168. "7.1":"y",
  169. "8":"y",
  170. "9":"y",
  171. "9.1":"y",
  172. "10":"y",
  173. "TP":"y"
  174. },
  175. "opera":{
  176. "9":"n",
  177. "9.5-9.6":"n",
  178. "10.0-10.1":"n",
  179. "10.5":"n",
  180. "10.6":"n",
  181. "11":"n",
  182. "11.1":"n",
  183. "11.5":"n",
  184. "11.6":"n",
  185. "12":"n",
  186. "12.1":"n",
  187. "15":"y",
  188. "16":"y",
  189. "17":"y",
  190. "18":"y",
  191. "19":"y",
  192. "20":"y",
  193. "21":"y",
  194. "22":"y",
  195. "23":"y",
  196. "24":"y",
  197. "25":"y",
  198. "26":"y",
  199. "27":"y",
  200. "28":"y",
  201. "29":"y",
  202. "30":"y",
  203. "31":"y",
  204. "32":"y",
  205. "33":"y",
  206. "34":"y",
  207. "35":"y",
  208. "36":"y",
  209. "37":"y",
  210. "38":"y",
  211. "39":"y",
  212. "40":"y",
  213. "41":"y",
  214. "42":"y",
  215. "43":"y",
  216. "44":"y"
  217. },
  218. "ios_saf":{
  219. "3.2":"n",
  220. "4.0-4.1":"n",
  221. "4.2-4.3":"n",
  222. "5.0-5.1":"a #2",
  223. "6.0-6.1":"y #2",
  224. "7.0-7.1":"y",
  225. "8":"y",
  226. "8.1-8.4":"y",
  227. "9.0-9.2":"y",
  228. "9.3":"y",
  229. "10-10.1":"y"
  230. },
  231. "op_mini":{
  232. "all":"n"
  233. },
  234. "android":{
  235. "2.1":"n",
  236. "2.2":"n",
  237. "2.3":"n",
  238. "3":"n",
  239. "4":"n",
  240. "4.1":"n",
  241. "4.2-4.3":"n",
  242. "4.4":"y",
  243. "4.4.3-4.4.4":"y",
  244. "53":"y"
  245. },
  246. "bb":{
  247. "7":"n",
  248. "10":"y #2"
  249. },
  250. "op_mob":{
  251. "10":"n",
  252. "11":"n",
  253. "11.1":"n",
  254. "11.5":"n",
  255. "12":"n",
  256. "12.1":"n",
  257. "37":"y"
  258. },
  259. "and_chr":{
  260. "55":"y"
  261. },
  262. "and_ff":{
  263. "50":"y"
  264. },
  265. "ie_mob":{
  266. "10":"a #1",
  267. "11":"a #1"
  268. },
  269. "and_uc":{
  270. "11":"y #2"
  271. },
  272. "samsung":{
  273. "4":"y"
  274. }
  275. },
  276. "notes":"The standard HTTP header is `Content-Security-Policy` which is used unless otherwise noted.",
  277. "notes_by_num":{
  278. "1":"Supported through the `X-Content-Security-Policy` header",
  279. "2":"Supported through the `X-Webkit-CSP` header"
  280. },
  281. "usage_perc_y":87.52,
  282. "usage_perc_a":4.39,
  283. "ucprefix":false,
  284. "parent":"",
  285. "keywords":"csp,security,header",
  286. "ie_id":"contentsecuritypolicy",
  287. "chrome_id":"5205088045891584",
  288. "firefox_id":"",
  289. "webkit_id":"",
  290. "shown":true
  291. }