The same-origin script row is allowed.

highlighted = computed this step

A same-origin script is allowed

The decision row treats the pinned script path as coming from self.

/app.js allowed\text{/app.js allowed}
Same-origin scriptThe script decisions and empty response body are recomputed from the pinned CSP response.Same-origin script - app.example allows self scripts and blocks inline scriptsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/pageparsedrequest lineversionHTTP/1.1parsedheaderHostapp.exampleexactheaderContent-Security-Policydefault-src 'self'; script-src 'self'exactdirectivedefault-srcselfselfdirectivescript-srcselfselfscript decision/app.jsallowedsame originscript decisioninline scriptblockednot selfstatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostapp.exampleexactcheckstatus200 OKokcheckdefault-srcselfselfcheckscript-srcselfselfchecksame-origin scriptallowedallowedcheckinline scriptblockedblockedchecksent body bytes0empty

The decision uses script-src

The script source row says self, so the same-origin script row says allowed.

script-src selfallowed\text{script-src self} \rightarrow \text{allowed}
Same-origin scriptThe script decisions and empty response body are recomputed from the pinned CSP response.Same-origin script - app.example allows self scripts and blocks inline scriptsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/pageparsedrequest lineversionHTTP/1.1parsedheaderHostapp.exampleexactheaderContent-Security-Policydefault-src 'self'; script-src 'self'exactdirectivedefault-srcselfselfdirectivescript-srcselfselfscript decision/app.jsallowedsame originscript decisioninline scriptblockednot selfstatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostapp.exampleexactcheckstatus200 OKokcheckdefault-srcselfselfcheckscript-srcselfselfchecksame-origin scriptallowedallowedcheckinline scriptblockedblockedchecksent body bytes0empty

The page does not load a script

The table is a static checked model, not browser script execution.

static decision row\text{static decision row}
Same-origin scriptThe script decisions and empty response body are recomputed from the pinned CSP response.Same-origin script - app.example allows self scripts and blocks inline scriptsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/pageparsedrequest lineversionHTTP/1.1parsedheaderHostapp.exampleexactheaderContent-Security-Policydefault-src 'self'; script-src 'self'exactdirectivedefault-srcselfselfdirectivescript-srcselfselfscript decision/app.jsallowedsame originscript decisioninline scriptblockednot selfstatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostapp.exampleexactcheckstatus200 OKokcheckdefault-srcselfselfcheckscript-srcselfselfchecksame-origin scriptallowedallowedcheckinline scriptblockedblockedchecksent body bytes0empty

Summary

The same-origin script row is allowed by the pinned self policy.

same-origin decision checked\text{same-origin decision checked}
Same-origin scriptThe script decisions and empty response body are recomputed from the pinned CSP response.Same-origin script - app.example allows self scripts and blocks inline scriptsectionnamevaluecheckrequest linemethodGETparsedrequest linepath/pageparsedrequest lineversionHTTP/1.1parsedheaderHostapp.exampleexactheaderContent-Security-Policydefault-src 'self'; script-src 'self'exactdirectivedefault-srcselfselfdirectivescript-srcselfselfscript decision/app.jsallowedsame originscript decisioninline scriptblockednot selfstatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostapp.exampleexactcheckstatus200 OKokcheckdefault-srcselfselfcheckscript-srcselfselfchecksame-origin scriptallowedallowedcheckinline scriptblockedblockedchecksent body bytes0empty