Image is allowed here:


iframe with srcdoc attribute and very restrictive csp not allowing javascript or any external resources:


This link should always be allowed to execute javascript: Trigger alert