csp.php 616 B

12345678910111213141516171819202122
  1. <?php
  2. # Support: Firefox
  3. header("X-Content-Security-Policy: default-src 'self';");
  4. # Support: Webkit, Safari 5
  5. # http://stackoverflow.com/questions/13663302/why-does-my-content-security-policy-work-everywhere-but-safari
  6. header("X-WebKit-CSP: script-src " . $_SERVER["HTTP_HOST"] . " 'self'");
  7. header("Content-Security-Policy: default-src 'self'");
  8. ?>
  9. <!DOCTYPE html>
  10. <html>
  11. <head>
  12. <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
  13. <title>CSP Test Page</title>
  14. <script src="../../jquery.js"></script>
  15. <script src="csp.js"></script>
  16. </head>
  17. <body>
  18. <p>CSP Test Page</p>
  19. </body>
  20. </html>