118
edits
(→Syntax) |
|||
| Line 11: | Line 11: | ||
future-rule = (anything but ",") | future-rule = (anything but ",") | ||
known-rule = *SP directive [ 1*SP origin-list ] *SP | known-rule = *SP directive [ 1*SP origin-list ] *SP | ||
directive = (see | directive = (see individual modules) | ||
origin-list = origin-descriptor [ 1*SP origin-list] | origin-list = origin-descriptor [ 1*SP origin-list] | ||
origin-descriptor = "none" / "self" / "*" / [scheme "://"] host-descriptor | origin-descriptor = "none" / "self" / "*" / [scheme "://"] host-descriptor | ||
| Line 17: | Line 17: | ||
qualified-host-name = dns-label "." host-name | qualified-host-name = dns-label "." host-name | ||
host-name = dns-label ["." host-name] | host-name = dns-label ["." host-name] | ||
</pre> | </pre> | ||
The browser MUST ignore any X-Content-Security-Policy header fields occurring in an HTML meta tag or in the Trailer headers. The semantics of these directives are described in the following section. | The browser MUST ignore any X-Content-Security-Policy header fields occurring in an HTML meta tag or in the Trailer headers. The semantics of these directives are described in the following section. | ||
edits