The HTTP Content-Security-Policy img-src directive specifies valid sources of images and favicons.
| CSP version | 1 |
|---|---|
| Directive type | Fetch directive |
default-src fallback | Yes. If this directive is absent, the user agent will look for the default-src directive. |