Script-src directive of the content security policy July 8, 2019 16 32 64 128 Script src directive of the content security policy Because it does not appear in the script src directive of the content security policy Content spoofing poc Content-security-policy script-src *