CSP: img-src
CSP: img-src
The HTTP Content-Security-Policy
img-src
directive specifies valid sources of images and favicons.
CSP version |
1 |
Directive type |
Fetch directive |
default-src fallback |
Yes. If this directive is absent, the user agent will look for the default-src directive. |
Syntax
One or more sources can be allowed for the img-src
policy:
Violation cases
Given this CSP header:
The following <img>
is blocked and won't load:
<img src="https://not-example.com/foo.jpg" alt="example picture" />
Specifications
Browser compatibility
|
Desktop |
Mobile |
|
Chrome |
Edge |
Firefox |
Internet Explorer |
Opera |
Safari |
WebView Android |
Chrome Android |
Firefox for Android |
Opera Android |
Safari on IOS |
Samsung Internet |
img-src |
25
|
14
|
23
|
No
|
15
|
7
|
Yes
|
Yes
|
23
|
Yes
|
7
|
Yes
|