CSP: font-src
CSP: font-src
The HTTP Content-Security-Policy
(CSP) font-src
directive specifies valid sources for fonts loaded using @font-face
.
CSP version |
1 |
Directive type |
Fetch directive |
default-src fallback |
Yes. If this directive is absent, the user agent will look for the default-src directive. |
Syntax
One or more sources can be allowed for the font-src
policy:
Violation cases
Given this CSP header:
The following font resource loading is blocked and won't load:
<style>
@font-face {
font-family: "MyFont";
src: url("https://not-example.com/font");
}
body {
font-family: "MyFont";
}
</style>
Specifications
Browser compatibility
|
Desktop |
Mobile |
|
Chrome |
Edge |
Firefox |
Internet Explorer |
Opera |
Safari |
WebView Android |
Chrome Android |
Firefox for Android |
Opera Android |
Safari on IOS |
Samsung Internet |
font-src |
25
|
14
|
23
|
No
|
15
|
7
|
Yes
|
Yes
|
23
|
Yes
|
7
|
Yes
|