← Back to plugin index

Loginapp UI Content Security Policy

Description
Enables a Content Security Policy (CSP) for the Loginapp UI.
Type name
LoginappUiContentSecurityPolicy
Class
com.airlock.iam.login.rest.application.configuration.LoginappUiContentSecurityPolicyConfig
May be used by
Properties
Content Security Policy (contentSecurityPolicy)
Description

This property can be used to define a custom policy.

The default policy requires to insert a nonce into script tags. Script tags that do not include a nonce will be blocked.

The placeholder '${cspNonce}' in the policy will be replaced with a fresh, randomly generated nonce for each request. The same nonce must be present in all policy relevant tags that were generated by a specific request.

Known use cases requiring CSP customization

  • IAM is embedded in an (i)frame: frame-ancestors directive must be relaxed.

Security Warning: The default CSP was designed to offer a good level of security and maintainability. The CSP is validated to work with IAM (see limitations above). Defining a custom CSP may reduce the level of security and may lead to browsers blocking IAM pages. Therefore, the security benefits of a custom policy must be evaluated carefully and IAM must be tested to work with the policy.

Attributes
String
Optional
Default value
default-src 'self'; object-src 'none'; script-src ${cspNonce} 'strict-dynamic' 'self'; img-src 'self' data: https://api.futurae.com; connect-src 'self' https://api.futurae.com wss://api.futurae.com; base-uri 'self'; frame-ancestors 'none';
YAML Template (with default values)

type: LoginappUiContentSecurityPolicy
id: LoginappUiContentSecurityPolicy-xxxxxx
displayName: 
comment: 
properties:
  contentSecurityPolicy: default-src 'self'; object-src 'none'; script-src ${cspNonce} 'strict-dynamic' 'self'; img-src 'self' data: https://api.futurae.com; connect-src 'self' https://api.futurae.com wss://api.futurae.com; base-uri 'self'; frame-ancestors 'none';