Default Attribute
self
Policy Description
The HTTP Content-Security-Policy (CSP) navigate-to directive restricts the URLs to which a document can initiate navigations by any means including <form>
 (if form-action is not specified), <a>
, window.location, window.open, etc. This is an enforcement on what navigations this document initiates not on what this document is allowed to navigate to.