URL and eval hashes in CSP script-src

This feature introduces url- and eval- hashes to be used in script-src directives in Content Security Policy. It enables developers to write a strict CSP that only relies on hash and nonce based policies, without having to use permissive hostname based allowlists or unsafe-eval.
Trial Expiration Date

August 25, 2026

English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Microsoft Privacy Manage cookies Terms of use Trademarks Safety & eco Recycling About our ads