SecurityPolicyViolationEvent: originalPolicy property
Baseline Widely available
This feature is well established and works across many devices and browser versions. It’s been available across browsers since August 2016.
Note: This feature is available in Web Workers.
The originalPolicy
read-only property of the SecurityPolicyViolationEvent
interface is a string containing the Content Security Policy (CSP) whose enforcement uncovered the violation.
Value
A string representing the policy whose enforcement uncovered the violation.
This is the string in the Content-Security-Policy
HTTP header that contains the list of directives and their values that make the CSP policy.
Examples
js
document.addEventListener("securitypolicyviolation", (e) => {
console.log(e.originalPolicy);
});
Specifications
Specification |
---|
Content Security Policy Level 3 # dom-securitypolicyviolationevent-originalpolicy |
Browser compatibility
BCD tables only load in the browser