Note: This feature is available in Web Workers.
The SecurityPolicyViolationEvent interface inherits from Event, and represents the event object of a securitypolicyviolation event sent on an Element, Document, or worker when its Content Security Policy (CSP) is violated.
SecurityPolicyViolationEvent()Creates a new SecurityPolicyViolationEvent object instance.
SecurityPolicyViolationEvent.blockedURI Read onlyA string representing the URI of the resource that was blocked because it violates a policy.
SecurityPolicyViolationEvent.columnNumber Read onlyThe column number in the document or worker at which the violation occurred.
SecurityPolicyViolationEvent.disposition Read onlyA string indicating whether the user agent is configured to enforce or just report the policy violation.
SecurityPolicyViolationEvent.documentURI Read onlyA string representing the URI of the document or worker in which the violation occurred.
SecurityPolicyViolationEvent.effectiveDirective Read onlyA string representing the directive that was violated.
SecurityPolicyViolationEvent.lineNumber Read onlyThe line number in the document or worker at which the violation occurred.
SecurityPolicyViolationEvent.originalPolicy Read onlyA string containing the policy whose enforcement caused the violation.
SecurityPolicyViolationEvent.referrer Read onlyA string representing the URL for the referrer of the resources whose policy was violated, or null.
SecurityPolicyViolationEvent.sample Read onlyA string representing a sample of the resource that caused the violation, usually the first 40 characters. This will only be populated if the resource is an inline script, event handler, or style — external resources causing a violation will not generate a sample.
SecurityPolicyViolationEvent.sourceFile Read onlyIf the violation occurred as a result of a script, this will be the URL of the script; otherwise, it will be null. Both columnNumber and lineNumber should have non-null values if this property is not null.
SecurityPolicyViolationEvent.statusCode Read onlyA number representing the HTTP status code of the document or worker in which the violation occurred.
SecurityPolicyViolationEvent.violatedDirective Read onlyA string representing the directive that was violated. This is a historical alias of effectiveDirective.
document.addEventListener("securitypolicyviolation", (e) => {
console.log(e.blockedURI);
console.log(e.violatedDirective);
console.log(e.originalPolicy);
});CSPViolationReportsecuritypolicyviolation event of the Element interfacesecuritypolicyviolation event of the Document interfacesecuritypolicyviolation event of the WorkerGlobalScope interface