Available from version 1.32.0
Modify the allowed CSP script sources.
Define function:
public static function onContentSecurityPolicyScriptSource( array &scriptSrc, array $policyConfig, int $mode ) { ... }
Attach hook:

In extension.json:

	"Hooks": {
		"ContentSecurityPolicyScriptSource": "MyExtensionHooks::onContentSecurityPolicyScriptSource"
Called from:File(s): ContentSecurityPolicy.php

Note that you also have to use ContentSecurityPolicyDefaultSource if you want non-script sources to be loaded from whatever you add.


  • &$scriptSrc: Array of Content-Security-Policy directives
  • $policyConfig: Current configuration for the Content-Security-Policy header
  • $mode: ContentSecurityPolicy::REPORT_ONLY_MODE or ContentSecurityPolicy::FULL_MODE depending on type of header