@@ -1708,15 +1708,16 @@ <h4 id="directive-default-src">`default-src`</h4>
1708
1708
will have the same behavior as the following header:
1709
1709
1710
1710
< pre >
1711
- < a > Content-Security-Policy</ a > : < a > child-src</ a > < a grammar > 'self'</ a > ;
1712
- < a > connect-src</ a > < a grammar > 'self'</ a > ;
1711
+ < a > Content-Security-Policy</ a > : < a > connect-src</ a > < a grammar > 'self'</ a > ;
1713
1712
< a > font-src</ a > < a grammar > 'self'</ a > ;
1713
+ < a > frame-src</ a > < a grammar > 'self'</ a > ;
1714
1714
< a > img-src</ a > < a grammar > 'self'</ a > ;
1715
1715
< a > manifest-src</ a > < a grammar > 'self'</ a > ;
1716
1716
< a > media-src</ a > < a grammar > 'self'</ a > ;
1717
1717
< a > object-src</ a > < a grammar > 'self'</ a > ;
1718
1718
< a > script-src</ a > < a grammar > 'self'</ a > ;
1719
- < a > style-src</ a > < a grammar > 'self'</ a >
1719
+ < a > style-src</ a > < a grammar > 'self'</ a > ;
1720
+ < a > worker-src</ a > < a grammar > 'self'</ a >
1720
1721
</ pre >
1721
1722
1722
1723
That is, when `default-src` is set, every < a > fetch directive</ a > that isn't
@@ -1734,15 +1735,16 @@ <h4 id="directive-default-src">`default-src`</h4>
1734
1735
will have the same behavior as the following header:
1735
1736
1736
1737
< pre >
1737
- < a > Content-Security-Policy</ a > : < a > child-src</ a > < a grammar > 'self'</ a > ;
1738
- < a > connect-src</ a > < a grammar > 'self'</ a > ;
1738
+ < a > Content-Security-Policy</ a > : < a > connect-src</ a > < a grammar > 'self'</ a > ;
1739
1739
< a > font-src</ a > < a grammar > 'self'</ a > ;
1740
+ < a > frame-src</ a > < a grammar > 'self'</ a > ;
1740
1741
< a > img-src</ a > < a grammar > 'self'</ a > ;
1741
1742
< a > manifest-src</ a > < a grammar > 'self'</ a > ;
1742
1743
< a > media-src</ a > < a grammar > 'self'</ a > ;
1743
1744
< a > object-src</ a > < a grammar > 'self'</ a > ;
1744
1745
< a > script-src</ a > https://example.com;
1745
- < a > style-src</ a > < a grammar > 'self'</ a >
1746
+ < a > style-src</ a > < a grammar > 'self'</ a > ;
1747
+ < a > worker-src</ a > < a grammar > 'self'</ a >
1746
1748
</ pre >
1747
1749
1748
1750
Given this behavior, one good way to build a policy for a site would be to
0 commit comments