web api interface
SecurityPolicyViolationEvent
Available in workers
The SecurityPolicyViolationEvent interface inherits from Event, and represents the event object of a securitypolicyviolation event sent on an Element, Document, or worker when its Content Security Policy (CSP) is violated.
Constructor
SecurityPolicyViolationEvent()- : Creates a new
SecurityPolicyViolationEventobject instance.
- : Creates a new
Instance properties
blockedURIRead only- : A string representing the URI of the resource that was blocked because it violates a policy.
columnNumberRead only- : The column number in the document or worker at which the violation occurred.
dispositionRead only- : A string indicating whether the user agent is configured to enforce or just report the policy violation.
documentURIRead only- : A string representing the URI of the document or worker in which the violation occurred.
effectiveDirectiveRead only- : A string representing the directive that was violated.
lineNumberRead only- : The line number in the document or worker at which the violation occurred.
originalPolicyRead only- : A string containing the policy whose enforcement caused the violation.
referrerRead only- : A string representing the URL for the referrer of the resources whose policy was violated, or
null.
- : A string representing the URL for the referrer of the resources whose policy was violated, or
sampleRead only- : A string representing a sample of the resource that caused the violation, usually the first 40 characters. This will only be populated if the resource is an inline script, event handler, or style — external resources causing a violation will not generate a sample.
sourceFileRead only- : If the violation occurred as a result of a script, this will be the URL of the script; otherwise, it will be
null. BothcolumnNumberandlineNumbershould have non-null values if this property is notnull.
- : If the violation occurred as a result of a script, this will be the URL of the script; otherwise, it will be
statusCodeRead only- : A number representing the HTTP status code of the document or worker in which the violation occurred.
violatedDirectiveRead only- : A string representing the directive that was violated.
This is a historical alias of
effectiveDirective.
- : A string representing the directive that was violated.
This is a historical alias of
Examples
document.addEventListener("securitypolicyviolation", (e) => {
console.log(e.blockedURI);
console.log(e.violatedDirective);
console.log(e.originalPolicy);
});
Specifications
SpecificationsStandards references are available on the canonical MDN page.
Browser compatibility
Browser compatibilityCompatibility data is available on the canonical MDN page.
See also
- HTTP Content Security Policy (CSP)
CSPViolationReport- The
securitypolicyviolationevent of theElementinterface - The
securitypolicyviolationevent of theDocumentinterface - The
securitypolicyviolationevent of theWorkerGlobalScopeinterface