CSPViolationReport: documentURL property

Baseline 2026
Newly available

Since March 2026, this feature works across the latest devices and browser versions. This feature might not work in older devices or browsers.

The documentURL property of the CSPViolationReport dictionary is a string that represents the URL of the document or worker that violated the Content Security Policy (CSP).

Value

A string containing the URL of the document or worker that violated the CSP.

Examples

CSP inline script violation showing referrer

This example triggers a CSP violation using an inline script, and reports the violation using a ReportingObserver. We navigate to the page from another page and log the referrer, documentURL, and blockedURL.

HTML

First we define our referrer page /bounce/index.html. This page just contains a link to another page ../report_sample/index.html.

html
<!doctype html>
<html lang="en">
  <head>
    <meta charset="UTF-8" />
    <meta name="viewport" content="width=device-width, initial-scale=1.0" />
  </head>
  <body>
    <ul>
      <li><a href="../report_sample/">report sample</a></li>
    </ul>
  </body>
</html>

The ../report_sample/index.html HTML file is defined below. This uses the <meta> element to set the Content-Security-Policy script-src-elem to self, which allows scripts to be loaded from the same domain, but does not allow inline scripts to be executed. The document also includes an inline script, which will trigger a CSP violation.

html
<!doctype html>
<!-- /report_sample/index.html -->
<html lang="en">
  <head>
    <meta
      http-equiv="Content-Security-Policy"
      content="script-src-elem 'self' 'report-sample'" />
    <script src="main.js"></script>
  </head>
  <body>
    <script>
      const int = 4;
    </script>
  </body>
</html>

JavaScript (main.js)

The report sample above also loads the external script main.js, which is shown below. Because this is loaded from the same domain as the HTML, it is not blocked by the CSP.

The script creates a new ReportingObserver to observe content violation reports of type "csp-violation". Each time the callback function is invoked, we get the body of the first entry of the reports array, and use it to log the violation documentURL, referrer, and blockedURL to the console.

js
// main.js
const observer = new ReportingObserver(
  (reports, observer) => {
    console.log(`documentURL: ${reports[0].body.documentURL}`);
    console.log(`referrer: ${reports[0].body.referrer}`);
    console.log(`blockedURL: ${reports[0].body.blockedURL}`);
  },
  {
    types: ["csp-violation"],
    buffered: true,
  },
);

observer.observe();

Note that while there might be multiple reports in the returned array, for brevity we only log the values of the first element.

Results

The console output for the above code would look a bit like that below (the site will depend on how the pages are served):

documentURL: http://127.0.0.1:9999/report_sample/
referrer: http://127.0.0.1:9999/bounce/
blockedURL: inline

Note that referrer is the page we navigated from, documentURL is the page with the CSP violation, and blockedURL is not a URL at all in this case, but an indication that the violation was caused by an inline script.

Specifications

Specification
Content Security Policy Level 3
# reporting

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
csp-violation report type
Chrome – Full support
Chrome 74 (Release date: 2019-04-23)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 149 (Release date: 2026-03-24)
footnote Full support
Opera – Full support
Opera 56 (Release date: 2018-09-25)
footnote Full support
Safari – Full support
Safari 18.4 (Release date: 2025-03-31)
footnote Full support
Chrome Android – Full support
Chrome Android 74 (Release date: 2019-04-24)
footnote Full support
Firefox for Android – Full support
Firefox for Android 149 (Release date: 2026-03-24)
footnote Full support
Opera Android – Full support
Opera Android 48 (Release date: 2018-11-08)
footnote Full support
Safari on iOS – Full support
Safari on iOS 18.4 (Release date: 2025-03-31)
footnote Full support
Samsung Internet – Full support
Samsung Internet 10 (Release date: 2019-08-22)
footnote Full support
WebView Android – Full support
WebView Android 74 (Release date: 2019-04-24)
footnote Full support
WebView on iOS – Full support
WebView on iOS 18.4 (Release date: 2025-03-31)
footnote Full support

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support

See also