Supported CSP Directives

DirectiveCategorySupported special valuesAlerting EnabledExample usage
script-srcScripts
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
Yesscript-src stripe.com *.stripe.com ;
connect-srcConnections
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
`
Yesconnect-src 'unsafe-inline' https://www.shop.stg.bcxg.sfcc-store-internal.net ;
default-srcDefault
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
Nodefault-src *.js.stripe.com 'unsafe-eval' 'unsafe-inline' ;
img-srcImages
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
Noimg-src 'self' 'unsafe-inline' ;
style-srcStyles
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
font-srcFonts
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
object-srcObjects
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
media-srcMedia
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
child-srcChild
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
form-actionForm actions
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
worker-srcWorkers
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
base-uriBase URI
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
manifest-srcManifests
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
frame-srcFrames
  • 'none'
  • 'self'
  • 'unsafe-inline'
  • 'unsafe-eval'
  • '<HASH>'
No
frame-ancestorsFrame ancestors
  • 'none'
  • 'self'
No
upgrade-insecure-requestsUpgrade insecure requestsN/ANo