{"slug": "connection-allowlists-secure-your-web-application-s-network-access", "title": "Connection allowlists: Secure your web application's network access", "summary": "Chrome 152 introduces connection allowlists, a security mechanism that lets developers enforce a deny-by-default network sandbox for documents and workers via a Connection-Allowlist HTTP response header. The feature uses URLPattern syntax to define permitted endpoints, blocks all redirects and WebRTC connections by default unless explicitly opted in, and supports a report-only mode through the Reporting API. Google positions the mechanism as a progressive enhancement to Content Security Policy, aimed at preventing malicious or hallucinated AI-generated code from exfiltrating data to unauthorized servers.", "body_md": "Published: September 23, 2026\n\nModern web apps are increasingly complex, integrating third-party\nscripts and sometimes dynamically generated code from generative AI. While these\nintegrations are powerful, they significantly increase the risk of data\nexfiltration. To address this risk, Chrome 152 introduces [connection\nallowlists](https://wicg.github.io/connection-allowlists/), a new security\nmechanism that lets you create a strict network sandbox for your documents and\nworkers.\n\n## The challenge of securing network communication\n\nYou need explicit control over the endpoints your pages communicate with to manage dependencies and secure your site's architecture. Malicious scripts or hallucinated AI-generated code can bypass app-level checks to send sensitive information to unauthorized servers.\n\nWhile [Content Security Policy (CSP)](https://developer.chrome.com/docs/privacy-security/csp) is a powerful\ntool for controlling what a page can load and execute, it is not designed to\nrestrict where a page communicates. CSP categorizes requests into specific\ntypes, which introduces excessive granularity when you just need a broad network\nboundary. Furthermore, CSP does not exhaustively cover all web platform APIs,\nomitting mechanisms like DNS prefetch, navigations, WebRTC, and more.\n\n## What are connection allowlists?\n\nConnection allowlists address these risks by making the browser the gatekeeper of all network connections originating from your page. They provide a direct and streamlined approach to managing explicit network requests initiated using Fetch and other web platform APIs.\n\nBy sending a `Connection-Allowlist` HTTP response header, you specify the exact\nURL patterns permitted for all network communication. This enforces a\nframework-level deny-by-default firewall. Before establishing any connection,\nthe browser verifies the destination against your allowlist and blocks it at the\nnetwork level if there is no match.\n\n## How to use connection allowlists\n\nThe policy uses the standardized `URLPattern` syntax to define allowed\nendpoints. *This policy is separate for each window or worker context*.\n\n### Basic configuration\n\nYou can use the `response-origin` token to dynamically add the origin from\nwhich the response is served to your allowlist, alongside any specific API\nendpoints.\n\n```\nConnection-Allowlist: (\"https://api.example.com/*\" response-origin)\n```\n\n### Handling redirects and WebRTC\n\nBy default, connection allowlists block all redirects and WebRTC connections. If an allowlist is enforced, any request resulting in a redirect is blocked unless you explicitly opt in.\n\n```\nConnection-Allowlist: (\"https://api.example.com/*\"); redirects=allow; webrtc=allow\n```\n\n### Reporting violations\n\nTo monitor potential breakages without interrupting service, you can deploy the\nfeature in report-only mode. This parses the policy and sends violation reports\nto a specified Reporting API endpoint without blocking the connections. Ensure\nyou also configure the `Reporting-Endpoints` HTTP response header to map your\nchosen endpoint name to an actual URL.\n\n```\nConnection-Allowlist-Report-Only: (\"https://trusted.com/*\"); report-to=security-endpoint\n```\n\n## Key use cases\n\nConnection allowlists are designed for high-security or dynamic environments. You'll find them particularly useful for:\n\n- **Securing generative AI:** If your web app executes generated or untrusted\ncode (like AI-generated UIs or development sandboxes), you can prevent that\ncode from exfiltrating data to external domains.\n- **Third-party oversight:** When embedding third-party scripts or web games,\nyou can guarantee they won't send data to unauthorized servers, even if they\nbecome compromised.\n- **Architectural safeguards:** You can enforce a strict network boundary\naround sensitive parts of your app, ensuring communication only ever\nhappens with your approved backends.\n\nThis feature can be used as a *progressive enhancement* to an existing Content\nSecurity Policy (CSP) based setup.\n\n## Test connection allowlists\n\nThe [connection allowlists\nfeature](https://chromestatus.com/feature/5175745573945344) is officially\navailable starting in Chrome 152. You can start protecting your web applications\ntoday by adding the header to your server's responses.\n\nTo test your configuration during development:\n\n1. Configure your local development server to send the `Connection-Allowlist` HTTP response header.\n2. Open Chrome DevTools and check the **Network** panel for requests that are\nblocked, or the**Issues** tab for detailed header parsing reports.", "url": "https://wpnews.pro/news/connection-allowlists-secure-your-web-application-s-network-access", "canonical_source": "https://developer.chrome.com/blog/connection-allowlist-announcement", "published_at": "2026-10-01 05:25:14+00:00", "updated_at": "2026-10-01 05:48:24.888320+00:00", "lang": "en", "topics": ["ai-safety", "developer-tools", "generative-ai"], "entities": ["Chrome 152", "Google", "Content Security Policy", "URLPattern", "Reporting API", "WebRTC"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/connection-allowlists-secure-your-web-application-s-network-access", "markdown": "https://wpnews.pro/news/connection-allowlists-secure-your-web-application-s-network-access.md", "text": "https://wpnews.pro/news/connection-allowlists-secure-your-web-application-s-network-access.txt", "jsonld": "https://wpnews.pro/news/connection-allowlists-secure-your-web-application-s-network-access.jsonld"}}