diff --git a/mercurial/help/config.txt b/mercurial/help/config.txt
--- a/mercurial/help/config.txt
+++ b/mercurial/help/config.txt
@@ -2111,6 +2111,20 @@ The full set of options is:
Name or email address of the person in charge of the repository.
(default: ui.username or ``$EMAIL`` or "unknown" if unset or empty)
+``csp``
+ Send a ``Content-Security-Policy`` HTTP header with this value.
+
+ The value may contain a special string ``%nonce%``, which will be replaced
+ by a randomly-generated one-time use value. If the value contains
+ ``%nonce%``, ``web.cache`` will be disabled, as caching undermines the
+ one-time property of the nonce. This nonce will also be inserted into
+ ``
+
+
+
+
+
+