An Introduction to Content Security Policy
html5rocks.com
html5rocks.com
Just look at how OWASP describes it:
> Content Security Policy requires careful tuning and precise definition of the policy. If enabled, CSP has significant impact on the way browser renders pages
If they want wide adoption they should really keep it simple. How often would sites need multiple URL whitelists for each (img/script/stylesheet)? A single whitelist would be fine. This is what I would have proposed:
Content-Security-Whitelist: self analytics.google.com mixpanel.com;
Content-Security-Policy:
scripts=<whitelist|*|none>;
styles=<whitelist|*|none>;
img=<whitelist|*|none>;
plugins=<whitelist|*|none>;
iframes=<whitelist|*|none>;
inline-scripts=<allow|deny>;
inline-styles=<allow|deny>;
insecure-requests=<upgrade|allow|deny>;