Common Values Reference
'self'
'none'
'unsafe-inline'
'unsafe-eval'
data:
blob:
https:
*
Directives
default-src
script-src
style-src
img-src
font-src
connect-src
frame-src
media-src
object-src
base-uri
form-action
frame-ancestors
upgrade-insecure-requests
HTTP Header
Copy
Content-Security-Policy: default-src 'self'
Meta Tag
Copy
<meta http-equiv="Content-Security-Policy" content="default-src 'self'">
</>
browserutils
CSP Header Generator