content_security_policy
Read More at MDN DocsSafe to Use
content_security_policy
is not safe to use.
It’s supported by 54% of global browsers.
Browsers
Version Breakdown
Full Support
Until Chrome 110, the object-src
directive was required with a secure source. From Chrome 111, the object-src
directive is optional.
Full Support
Until Edge 110, the object-src
directive was required with a secure source. From Edge 111, the object-src
directive is optional.
Full Support
Firefox does not support 'http://127.0.0.1' or 'http://localhost' as script sources: they must be served over HTTPS.
Until Firefox 105, the object-src
directive was required with a secure source. From Firefox 106, the object-src
directive is optional.
No Support
Full Support
Until Opera 96, the object-src
directive was required with a secure source. From Opera 97, the object-src
directive is optional.
Full Support
There is no requirement to include the object-src
directive.
Full Support
There is no requirement to include the object-src
directive.