WPT
wpt / trusted-types / script-enforcement-009.https.html
Spec: Trusted Types ↗
Runs: Chrome 155.0.8039.0 (wpt@6ec9fd59f, 2026-09-03) | Firefox 157.0a1 (wpt@6ec9fd59f, 2026-09-03) | Safari 251 preview (wpt@5ce815a83, 2026-08-27) | Ladybird 1.0-795e1 (wpt@7e3d005d7, 2026-09-03) | Servo Servo 0.6 (wpt@09159dcb3, 2026-09-02) | Blitz 188486089 (wpt@a95401e4e, 2026-09-02)
View on the Blitz WPT dashboard | Open test on wpt.live | wpt.fyi
| Chrome | Firefox | Safari | Ladybird | Servo | Blitz | |
|---|---|---|---|---|---|---|
| Total | 5/5 | 4/5 | 5/5 | 1/5 | 1/5 | NOT RUN |
| Subtest | Chrome | Firefox | Safari | Ladybird | Servo | Blitz |
|---|---|---|---|---|---|---|
| script-src CSP directive is properly set. | PASS | PASS | PASS | PASS | PASS | — |
| Untrusted SVGScriptElement with classic type uses the source text returned by the default policy for inline CSP check. | PASS | PASS | PASS | FAIL | FAIL | — |
| Untrusted SVGScriptElement of importmap type uses the source text returned by the default policy for inline CSP check. | PASS | PASS | PASS | FAIL | FAIL | — |
| Untrusted SVGScriptElement of module type uses the source text returned by the default policy for inline CSP check. | PASS | PASS | PASS | FAIL | FAIL | — |
| Untrusted SVGScriptElement of 2 importmap types use the source text returned by the default policy for inline CSP check. | PASS | FAIL | PASS | FAIL | FAIL | — |