Note: This feature is available in Web Workers.
The originalPolicy read-only property of the SecurityPolicyViolationEvent interface is a string containing the Content Security Policy (CSP) whose enforcement uncovered the violation.
A string representing the policy whose enforcement uncovered the violation.
This is the string in the Content-Security-Policy HTTP header that contains the list of directives and their values that make the CSP policy.
document.addEventListener("securitypolicyviolation", (e) => {
console.log(e.originalPolicy);
});