WPT
wpt / trusted-types / script-enforcement-009.https.html
Spec: Trusted Types ↗
Runs: Chrome 155.0.8038.0 (wpt@397d01d8e, 2026-09-02) | Firefox 157.0a1 (wpt@397d01d8e, 2026-09-02) | Safari 251 preview (wpt@5ce815a83, 2026-08-27) | Ladybird 1.0-5f6fa (wpt@b1a7025f8, 2026-09-02) | Servo Servo 0.5 (wpt@2ccd2cbf8, 2026-09-01) | Blitz 7727414ca (wpt@a95401e4e, 2026-09-02)
View on the Blitz WPT dashboard | Open test on wpt.live | wpt.fyi
| Chrome | Firefox | Safari | Ladybird | Servo | Blitz | |
|---|---|---|---|---|---|---|
| Total | 5/5 | 4/5 | 5/5 | 1/5 | 1/5 | NOT RUN |
| Subtest | Chrome | Firefox | Safari | Ladybird | Servo | Blitz |
|---|---|---|---|---|---|---|
| script-src CSP directive is properly set. | PASS | PASS | PASS | PASS | PASS | — |
| Untrusted SVGScriptElement with classic type uses the source text returned by the default policy for inline CSP check. | PASS | PASS | PASS | FAIL | FAIL | — |
| Untrusted SVGScriptElement of importmap type uses the source text returned by the default policy for inline CSP check. | PASS | PASS | PASS | FAIL | FAIL | — |
| Untrusted SVGScriptElement of module type uses the source text returned by the default policy for inline CSP check. | PASS | PASS | PASS | FAIL | FAIL | — |
| Untrusted SVGScriptElement of 2 importmap types use the source text returned by the default policy for inline CSP check. | PASS | FAIL | PASS | FAIL | FAIL | — |