The HTTP Content-Security-Policy
(CSP) script-src-attr
directive specifies valid sources for JavaScript inline event handlers. This includes only inline script event handlers like onclick
, but not URLs loaded directly into <script>
elements.
CSP version | 3 |
---|---|
Directive type | Fetch directive |
default-src fallback | Yes. If this directive is absent, the user agent will look for the script-src directive, and if both of them are absent, fallback to default-src directive. |