Content Security Policy
Info: Content Security Policy is available in brXM 15.0.0 and later.
brXM 15.0.0 and newer enable Content Security Policy (CSP) by default. The default policy is not highly restrictive because some legacy JavaScript libraries require "unsafe" features. Future releases will address these dependencies and further restrict the CSP.
CSP rules primarily control which domains can be used in elements such as <iframe>, <script>, and <style>. These restrictions directly impact Open UI extensions. To allow additional domains, you must update the CSP configuration in the repository at:
/hippo:configuration/hippo:modules/application-settings/hippo:moduleconfig/content-security-policy.
You can configure the following CSP directives:
- connect-src
- frame-ancestors
- frame-src
- img-src
- script-src
- style-src
- font-src