Available from version 1.32.0
Modify the allowed CSP script sources.
Define function:
public static function onContentSecurityPolicyScriptSource( array &scriptSrc, array $policyConfig, int $mode ) { ... }
Attach hook: In extension.json:
	"Hooks": {
		"ContentSecurityPolicyScriptSource": "MediaWiki\\Extension\\MyExtension\\Hooks::onContentSecurityPolicyScriptSource"
Called from: File(s): ContentSecurityPolicy.php
Interface: ContentSecurityPolicyScriptSourceHook.php

For more information about attaching hooks, see Manual:Hooks .
For examples of extensions using this hook, see Category:ContentSecurityPolicyScriptSource extensions.

Note that you also have to use ContentSecurityPolicyDefaultSource if you want non-script sources to be loaded from whatever you add.


  • &$scriptSrc: Array of Content-Security-Policy directives
  • $policyConfig: Current configuration for the Content-Security-Policy header
  • $mode: ContentSecurityPolicy::REPORT_ONLY_MODE or ContentSecurityPolicy::FULL_MODE depending on type of header