docs.rodeo

MDN Web Docs mirror

CSP: img-src

{{HTTPSidebar}} 

The HTTP {{HTTPHeader("Content-Security-Policy")}}  img-src directive specifies valid sources of images and favicons.

CSP version 1
Directive type `{{Glossary("Fetch directive")}}` 
`{{CSP("default-src")}}`  fallback Yes. If this directive is absent, the user agent will look for the default-src directive.

Syntax

Content-Security-Policy: img-src 'none';
Content-Security-Policy: img-src <source-expression-list>;

This directive may have one of the following values:

Examples

Violation cases

Given this CSP header:

Content-Security-Policy: img-src https://example.com/

The following {{HTMLElement("img")}}  is blocked and won’t load:

<img src="https://not-example.com/foo.jpg" alt="example picture" />

Specifications

{{Specifications}} 

Browser compatibility

{{Compat}} 

See also

In this article

View on MDN