CSP: manifest-src
CSP: manifest-src
The HTTP Content-Security-Policy
: manifest-src
directive specifies which manifest can be applied to the resource.
CSP version |
3 |
Directive type |
Fetch directive |
default-src fallback |
Yes. If this directive is absent, the user agent will look for the default-src directive. |
Syntax
One or more sources can be allowed for the manifest-src
policy:
Violation cases
Given this CSP header:
The following <link>
is blocked and won't load:
<link rel="manifest" href="https://not-example.com/manifest" />
Specifications
Browser compatibility
|
Desktop |
Mobile |
|
Chrome |
Edge |
Firefox |
Internet Explorer |
Opera |
Safari |
WebView Android |
Chrome Android |
Firefox for Android |
Opera Android |
Safari on IOS |
Samsung Internet |
manifest-src |
Yes
|
79
|
41
|
No
|
Yes
|
No
|
Yes
|
Yes
|
41
|
Yes
|
No
|
Yes
|