Adminapp Content Security Policy
Neither the Config Editor nor the Service Container are covered by this CSP.
contentSecurityPolicy) The default policy requires to insert a nonce into script tags. Script tags that do not include a nonce will be blocked.
The placeholder '${cspNonce}' in the policy will be replaced with a fresh, randomly generated nonce for each request. The same nonce must be present in all policy relevant tags that were generated by a specific request.
Known use cases requiring CSP customization
- IAM is embedded in an (i)frame: frame-ancestors directive must be relaxed.
Security Warning: The default CSP was designed to offer a good level of security and maintainability. The CSP is validated to work with IAM (see limitations above). Defining a custom CSP may reduce the level of security and may lead to browsers blocking IAM pages. Therefore, the security benefits of a custom policy must be evaluated carefully and IAM must be tested to work with the policy.
type: AdminappContentSecurityPolicy
id: AdminappContentSecurityPolicy-xxxxxx
displayName:
comment:
properties:
contentSecurityPolicy: default-src 'self'; object-src 'none'; script-src ${cspNonce} 'strict-dynamic' 'self'; img-src 'self' data:; connect-src 'self'; base-uri 'self'; frame-ancestors 'none';