default-srcFallback for other directives
script-srcValid sources for JavaScript
style-srcValid sources for stylesheets
img-srcValid sources for images
font-srcValid sources for fonts
connect-srcValid targets for fetch/XHR/WS
media-srcValid sources for audio/video
object-srcValid sources for plugins
frame-srcValid sources for iframes
child-srcValid sources for workers/frames
worker-srcValid sources for workers
base-uriRestricts base element URLs
form-actionValid targets for form submission
frame-ancestorsValid parents that can embed page