Firefox Tomorrow

web api interface

SecurityPolicyViolationEvent

View on MDN ↗

Available in workers

The SecurityPolicyViolationEvent interface inherits from Event, and represents the event object of a securitypolicyviolation event sent on an Element, Document, or worker when its Content Security Policy (CSP) is violated.

Constructor

Instance properties

  • blockedURI Read only
    • : A string representing the URI of the resource that was blocked because it violates a policy.
  • columnNumber Read only
    • : The column number in the document or worker at which the violation occurred.
  • disposition Read only
    • : A string indicating whether the user agent is configured to enforce or just report the policy violation.
  • documentURI Read only
    • : A string representing the URI of the document or worker in which the violation occurred.
  • effectiveDirective Read only
    • : A string representing the directive that was violated.
  • lineNumber Read only
    • : The line number in the document or worker at which the violation occurred.
  • originalPolicy Read only
    • : A string containing the policy whose enforcement caused the violation.
  • referrer Read only
    • : A string representing the URL for the referrer of the resources whose policy was violated, or null.
  • sample Read only
    • : A string representing a sample of the resource that caused the violation, usually the first 40 characters. This will only be populated if the resource is an inline script, event handler, or style — external resources causing a violation will not generate a sample.
  • sourceFile Read only
    • : If the violation occurred as a result of a script, this will be the URL of the script; otherwise, it will be null. Both columnNumber and lineNumber should have non-null values if this property is not null.
  • statusCode Read only
    • : A number representing the HTTP status code of the document or worker in which the violation occurred.
  • violatedDirective Read only
    • : A string representing the directive that was violated. This is a historical alias of effectiveDirective.

Examples

document.addEventListener("securitypolicyviolation", (e) => {
  console.log(e.blockedURI);
  console.log(e.violatedDirective);
  console.log(e.originalPolicy);
});

Specifications

SpecificationsStandards references are available on the canonical MDN page.

Browser compatibility

Browser compatibilityCompatibility data is available on the canonical MDN page.

See also