recommended_policy: {
    base-uri: string[];
    connect-src: string[];
    default-src: string[];
    font-src: string[];
    form-action: string[];
    frame-ancestors: string[];
    img-src: string[];
    manifest-src: string[];
    object-src: string[];
    script-src: string[];
    style-src: string[];
    upgrade-insecure-requests: boolean;
} = ...

Recommended policy for most sites.

Type declaration

  • base-uri: string[]
  • connect-src: string[]
  • default-src: string[]
  • font-src: string[]
  • form-action: string[]
  • frame-ancestors: string[]
  • img-src: string[]
  • manifest-src: string[]
  • object-src: string[]
  • script-src: string[]
  • style-src: string[]
  • upgrade-insecure-requests: boolean

See

content-security-policy.com - Content Security Policy Reference

Remarks

Here are the differences with the starter policy: