CSP: prefetch-src
CSP: prefetch-src
The HTTP Content-Security-Policy
(CSP) prefetch-src
directive specifies valid resources that may be prefetched or prerendered.
CSP version |
3 |
Directive type |
Fetch directive |
default-src fallback |
Yes. If this directive is absent, the user agent will look for the default-src directive. |
Syntax
One or more sources can be allowed for the prefetch-src
policy:
Given a page with the following Content Security Policy:
Fetches for the following code will return network errors, as the URLs provided do not match prefetch-src
's source list:
<link rel="prefetch" href="https://example.org/" />
<link rel="prerender" href="https://example.org/" />
Specifications
Browser compatibility
|
Desktop |
Mobile |
|
Chrome |
Edge |
Firefox |
Internet Explorer |
Opera |
Safari |
WebView Android |
Chrome Android |
Firefox for Android |
Opera Android |
Safari on IOS |
Samsung Internet |
prefetch-src |
No
|
No
|
No
|
No
|
No
|
No
|
No
|
No
|
No
|
No
|
No
|
No
|