Click here to download the Blitz Browser!

WPT

wpt / content-security-policy / embedded-enforcement / subsumption_algorithm-strict_dynamic.html

Spec: Content Security Policy: Embedded Enforcement ↗

Runs: Chrome 155.0.8041.0 (wpt@07d3da1fa, 2026-09-04) | Firefox 157.0a1 (wpt@4fbf9ef4d, 2026-09-04) | Safari 251 preview (wpt@5ce815a83, 2026-08-27) | Ladybird 1.0-a7825 (wpt@4fbf9ef4d, 2026-09-04) | Servo Servo 0.6 (wpt@7e3d005d7, 2026-09-03) | Blitz a50cb8971 (wpt@a95401e4e, 2026-09-03)

View on the Blitz WPT dashboard | Open test on wpt.live | wpt.fyi

ChromeFirefoxSafariLadybirdServoBlitz
Total11/118/118/118/118/11NOT RUN
SubtestChromeFirefoxSafariLadybirdServoBlitz
'strict-dynamic' is ineffective for `style-src`.PASSPASSPASSPASSPASS
'strict-dynamic' is ineffective for `img-src`.PASSPASSPASSPASSPASS
'strict-dynamic' is ineffective for `frame-src`.PASSPASSPASSPASSPASS
'strict-dynamic' is ineffective for `child-src`.PASSPASSPASSPASSPASS
'strict-dynamic' is effective only for `script-src`.PASSFAILFAILFAILFAIL
'strict-dynamic' is properly handled for finding effective policy.PASSFAILFAILFAILFAIL
'strict-dynamic' makes host source expressions ineffective.PASSPASSPASSPASSPASS
'strict-dynamic' makes scheme source expressions ineffective.PASSPASSPASSPASSPASS
'strict-dynamic' makes 'self' ineffective.PASSPASSPASSPASSPASS
'strict-dynamic' makes 'unsafe-inline' ineffective.PASSPASSPASSPASSPASS
'strict-dynamic' has to be allowed by required csp if it is present in returned csp.PASSFAILFAILFAILFAIL