- protocol/scheme (optional)
- hostname (mandatory)
- path (optional)
Notably, there is no query portion or fragment portion; browsers are expected to ignore those. Path matching works like a prefix if it ends in a slash. If it doesn't, only exactly that path matches.In CSP3, the secure protocol/scheme (https, wss) always matches, even if you explicitly specify http://. In CSP2, the implicit scheme matches either; an explicit scheme only matches that scheme. This is typically not useful behavior because you probably have HSTS anyway, so people just use hostnames and only rarely specify the protocol. Most values in practice seem to just be hostnames in general; paths too are rare.
With multiple domains, you at least can limit the blast radius of an XSS; on the same domain, most protections can be circumvented. E.g. there's no cors protection, so if different apps use different implementations of csrf, just fetch a the other app's page over XHR and parse out it's csrf token; it's probably their or in a cookie which you should be able to read.
https://developer.mozilla.org/en-US/docs/Web/API/Document/co...
for anyone interested in the topic, https://www.usenix.org/system/files/conference/usenixsecurit... is a must read