Default Web browser behaviour without Content-Security-Policy

Viewed 214

What is the default (modern) Web browsers behavior if a website does not set Content-Security-Policy in response header or in HTML <meta>. Here is list of different browser vendors compatibility.

Seems I can't find it under W3C CSP specification.

Default Web browser behavior without setting Access-Control-Allow-Origin is same origin policy. Adding Access-Control-Allow-Origin with more websites make it more permissive.

How about Content-Security-Policy? Without setting it, does it allow all (like this) or restrict to self only?

0 Answers
Related