Content executionTest link available
Policy parsing and enforcement behaviour across the CSP test suite.
Limit: Suite coverage does not establish that an application's policy is complete, effective, or deployed on every response.
Content executionTest link available
Nonce source parsing and script authorisation behaviour.
Limit: The mapping covers browser behaviour, not nonce unpredictability, per-response generation, reuse, or disclosure.
Content executionTest link available
Hash source parsing and authorisation for inline script and style content.
Limit: The mapping does not establish that deployed hashes match every intended resource or remain current.
Content executionTest link available
strict-dynamic parsing, trust propagation, and fallback interactions.
Limit: Passing behaviour does not establish that an application's trusted loaders are safe.
Content executionTest link available
Base URL authorisation and blocking behaviour.
Limit: The suite does not establish that an application prevents every unsafe absolute URL.
Content executionTest link available
Embedding authorisation across same-origin, cross-origin, nested, and sandboxed cases.
Limit: The mapping does not establish that the deployed allowlist matches an application's intended embedding relationships.
Content executionTest link available
Form destination authorisation, redirects, and target behaviour.
Limit: The suite does not evaluate scripted requests, server authorisation, or whether every legitimate destination was inventoried.
Content executionTest link available
Eligible request rewriting and mixed-content interactions.
Limit: The mapping does not prove that every upgraded endpoint supports correct HTTPS.
Content executionTest link available
Sandbox token behaviour across frames, workers, redirects, and navigations.
Limit: The suite cannot determine whether an application's selected sandbox tokens grant excessive capability.
Content executionTest link available
Trusted Types APIs, policy behaviour, CSP enforcement, and protected DOM sinks.
Limit: The mapping does not establish complete sink coverage or the safety of application-authored policies.
Content executionTest link available
Integrity metadata parsing, digest matching, fetching, and CSP interactions.
Limit: The suite does not establish that a deployment supplies current integrity metadata for every eligible resource.
Content executionTest link available
Integrity-Policy parsing, blocking, report-only behaviour, destinations, sources, and reporting integration.
Limit: The suite does not establish that every production resource carries current metadata or that reports are operationally reviewed.
Cross-origin isolationTest link available
Browsing-context isolation, opener relationships, reporting, and navigation behaviour.
Limit: The mapping does not establish compatibility with an application's popup and cross-window integrations.
Cross-origin isolationTest link available
Cross-origin resource opt-in and embedder-policy enforcement.
Limit: The suite does not establish that all production dependencies opt in correctly.
Cross-origin isolationTest link available
Resource-policy enforcement across fetch and embedding contexts.
Limit: The mapping does not determine the correct resource-sharing policy for an application.
Cross-origin isolationTest link available
Credential omission and embedding behaviour under credentialless COEP.
Limit: The suite does not establish that credential omission is suitable for every embedded resource.
Cross-origin isolationTest link available
Origin-keyed agent-cluster opt-in and browsing behaviour.
Limit: Agent clustering is not a guarantee of process isolation or an application authorisation boundary.
Cross-origin isolationTest link available
Sec-Fetch request-context header generation across request modes and destinations.
Limit: The mapping does not test an application's server-side resource-isolation policy.
Browser privacyTest link available
Policy parsing, inheritance, delegation, and feature-specific enforcement.
Limit: The suite does not establish that an application selected the correct capabilities or frame allowlists.
Transport and response hardeningNo exact test link
No exact suite mapping was retained at the reviewed revision.
No similar test is substituted when an exact link is unavailable.
Limit: Nearby HTTPS and navigation tests are not substituted for HSTS state, expiry, subdomain, or first-visit behaviour.
Transport and response hardeningTest link available
nosniff enforcement for relevant script, style, and fetch responses.
Limit: The suite does not establish that a deployment sends correct Content-Type values for every response.
Transport and response hardeningTest link available
Directive parsing and browser-held data clearing behaviour.
Limit: The mapping does not establish correct logout sequencing, server-side revocation, or coverage of every storage mechanism.
Browser privacyTest link available
Policy parsing and referrer delivery across navigation and resource contexts.
Limit: The suite does not establish that sensitive data is absent from URLs or other telemetry.
Browser privacyTest link available
SameSite parsing and cookie delivery across same-site and cross-site contexts.
Limit: The mapping does not establish that session cookies use an appropriate value or replace CSRF protection.
Browser privacyTest link available
Partition-key behaviour, redirects, subresources, and SameSite interactions.
Limit: The mapping does not establish that a deployment needs partitioned state or declares all required attributes.
Browser privacyNo exact test link
No exact suite mapping was retained at the reviewed revision.
No similar test is substituted when an exact link is unavailable.
Limit: General cookie tests are not substituted for the intended claim that script access is prevented by HttpOnly.
Browser privacyTest link available
__Secure-, __Host-, __Http-, and __Host-Http- prefix constraint behaviour.
Limit: Prefix enforcement does not establish sound session design or protection from every cookie-confusion attack.
AuthenticationTest link available
WebAuthn API and authenticator-availability behaviour within the WebAuthn suite.
Limit: The suite does not establish relying-party verification, recovery safety, or authenticator policy.
AuthenticationTest link available
PRF extension parsing and credential operation behaviour within the WebAuthn suite.
Limit: The mapping does not establish authenticator support in a user's environment or a safe key-recovery design.
AuthenticationTest link available
Conditional mediation and related PublicKeyCredential behaviour within the WebAuthn suite.
Limit: The suite does not establish a secure account, autofill, or recovery experience.