http permissions policy directive
Permissions-Policy: attribution-reporting directive
The HTTP Permissions-Policy header attribution-reporting directive controls whether the current document is allowed to use the Attribution Reporting API.
Specifically, where a defined policy blocks the use of this feature:
- Background
attributionsrcrequests won’t be made. - The
setAttributionReporting()method will throw an exception when called. - The
attributionReportingoption, when included on afetch()call, will cause it to throw an exception. - Registration headers (
Attribution-Reporting-Register-SourceandAttribution-Reporting-Register-Trigger) in HTTP responses on associated documents will be ignored.
Syntax
Permissions-Policy: attribution-reporting=<allowlist>;
<allowlist>- : A list of origins for which permission is granted to use the feature. See
Permissions-Policy> Syntax for more details.
- : A list of origins for which permission is granted to use the feature. See
Default policy
The default allowlist for attribution-reporting is *.
Specifications
SpecificationsStandards references are available on the canonical MDN page.
Browser compatibility
Browser compatibilityCompatibility data is available on the canonical MDN page.