The response carries a Content-Security-Policy header.

highlighted = computed this step

The response carries Content-Security-Policy

The policy row is parsed from the pinned response header.

Content-Security-Policy\text{Content-Security-Policy}
CSP headerThe request host, CSP policy directives, script decisions, empty body, and checks are recomputed from pinned bytes.CSP header - app.example allows self scripts and blocks inline scriptsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/pageparsedrequest lineversionHTTP/1.1parsedheaderHostapp.exampleexactheaderContent-Security-Policydefault-src 'self'; script-src 'self'exactdirectivedefault-srcselfselfdirectivescript-srcselfselfscript decision/app.jsallowedsame originscript decisioninline scriptblockednot selfstatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostapp.exampleexactcheckstatus200 OKokcheckdefault-srcselfselfcheckscript-srcselfselfchecksame-origin scriptallowedallowedcheckinline scriptblockedblockedchecksent body bytes0empty

The response status is OK

The status row stays separate from the policy row.

status=OK\text{status}=\text{OK}
CSP headerThe request host, CSP policy directives, script decisions, empty body, and checks are recomputed from pinned bytes.CSP header - app.example allows self scripts and blocks inline scriptsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/pageparsedrequest lineversionHTTP/1.1parsedheaderHostapp.exampleexactheaderContent-Security-Policydefault-src 'self'; script-src 'self'exactdirectivedefault-srcselfselfdirectivescript-srcselfselfscript decision/app.jsallowedsame originscript decisioninline scriptblockednot selfstatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostapp.exampleexactcheckstatus200 OKokcheckdefault-srcselfselfcheckscript-srcselfselfchecksame-origin scriptallowedallowedcheckinline scriptblockedblockedchecksent body bytes0empty

The response body is empty

Content-Length is 0 in this pinned response.

body bytes=0\text{body bytes}=0
CSP headerThe request host, CSP policy directives, script decisions, empty body, and checks are recomputed from pinned bytes.CSP header - app.example allows self scripts and blocks inline scriptsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/pageparsedrequest lineversionHTTP/1.1parsedheaderHostapp.exampleexactheaderContent-Security-Policydefault-src 'self'; script-src 'self'exactdirectivedefault-srcselfselfdirectivescript-srcselfselfscript decision/app.jsallowedsame originscript decisioninline scriptblockednot selfstatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostapp.exampleexactcheckstatus200 OKokcheckdefault-srcselfselfcheckscript-srcselfselfchecksame-origin scriptallowedallowedcheckinline scriptblockedblockedchecksent body bytes0empty

Summary

The CSP policy is a response header in this toy page.

CSP header checked\text{CSP header checked}
CSP headerThe request host, CSP policy directives, script decisions, empty body, and checks are recomputed from pinned bytes.CSP header - app.example allows self scripts and blocks inline scriptsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/pageparsedrequest lineversionHTTP/1.1parsedheaderHostapp.exampleexactheaderContent-Security-Policydefault-src 'self'; script-src 'self'exactdirectivedefault-srcselfselfdirectivescript-srcselfselfscript decision/app.jsallowedsame originscript decisioninline scriptblockednot selfstatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostapp.exampleexactcheckstatus200 OKokcheckdefault-srcselfselfcheckscript-srcselfselfchecksame-origin scriptallowedallowedcheckinline scriptblockedblockedchecksent body bytes0empty