← Back to plugin index

Adminapp Content Security Policy

Description
Enables a Content Security Policy (CSP) for the Adminapp.

Neither the Config Editor nor the Service Container are covered by this CSP.

Type name
AdminappContentSecurityPolicy
Class
com.airlock.iam.admin.application.configuration.csp.AdminappContentSecurityPolicyConfig
May be used by
Properties
Content Security Policy (contentSecurityPolicy)
Description
This property can be used to define a custom policy.

The default policy requires to insert a nonce into script tags. Script tags that do not include a nonce will be blocked.

The placeholder '${cspNonce}' in the policy will be replaced with a fresh, randomly generated nonce for each request. The same nonce must be present in all policy relevant tags that were generated by a specific request.

Known use cases requiring CSP customization

  • IAM is embedded in an (i)frame: frame-ancestors directive must be relaxed.

Security Warning: The default CSP was designed to offer a good level of security and maintainability. The CSP is validated to work with IAM (see limitations above). Defining a custom CSP may reduce the level of security and may lead to browsers blocking IAM pages. Therefore, the security benefits of a custom policy must be evaluated carefully and IAM must be tested to work with the policy.

Attributes
String
Optional
Default value
default-src 'self'; object-src 'none'; script-src ${cspNonce} 'strict-dynamic' 'self'; img-src 'self' data:; connect-src 'self'; base-uri 'self'; frame-ancestors 'none';
YAML Template (with default values)

type: AdminappContentSecurityPolicy
id: AdminappContentSecurityPolicy-xxxxxx
displayName: 
comment: 
properties:
  contentSecurityPolicy: default-src 'self'; object-src 'none'; script-src ${cspNonce} 'strict-dynamic' 'self'; img-src 'self' data:; connect-src 'self'; base-uri 'self'; frame-ancestors 'none';