The following tests demonstrate the core functionality of Content Security Policy. Grab a copy of Firefox and load this page to see how CSP works. For each individual test, a CSP-supporting browser will display PASS while a non-supporting browser will display FAIL. Each test also contains a comment showing the CSP header that was sent.
There is also additional debugging information provided on the JavaScript Error console. For example, loading the img-src test in a CSP-enabled build will produce (among others) the following message:
CSP debug: blocking request for http://hackmill.com/csp/tests/resources/1x1.gif