← Back to release summary

Content Security Policy Level 2

Category
Security
Type
New or changed feature
Status
Enabled by default (Chrome 40)
Intent stage
None

Summary

An evolution of the Content Security Policy specification, allowing developers to create a whitelist of sources of trusted content, and instructing the browser to only execute or render resources from those sources.

Standards & signals

View on chromestatus.com