“Cross-Origin-Resource-Policy” response header allows http servers to ask the browser to prevent cross-origin or cross-site embedding of the returned resource. It is complementary to the Cross-Origin Read Blocking feature and is especially valuable for resources not covered by CORB (which only protects HTML, XML and JSON). “Cross-Origin-Resource-Policy” is currently the only way to protect images against Spectre attacks or against compromised renderers.
Specification
Final published standard: Recommendation, Living Standard, Candidate Recommendation, or similar final form
Status in Chromium
Enabled by default
(tracking bug)
Consensus & Standardization
After a feature ships in Chrome, the values listed here are not guaranteed to be up to date.
- Positive
- Shipped/Shipping
- Positive
Owners
Search tags
corp, from-origin, cross-origin-resource-policy,Last updated on 2022-01-14