Content Security Policy

Info: Content Security Policy is available in brXM 15.0.0 and later.

brXM 15.0.0 and newer enable Content Security Policy (CSP) by default. The default policy is not highly restrictive because some legacy JavaScript libraries require "unsafe" features. Future releases will address these dependencies and further restrict the CSP.

CSP rules primarily control which domains can be used in elements such as <iframe>, <script>, and <style>. These restrictions directly impact Open UI extensions. To allow additional domains, you must update the CSP configuration in the repository at:

/hippo:configuration/hippo:modules/application-settings/hippo:moduleconfig/content-security-policy.

You can configure the following CSP directives:

  • connect-src
  • frame-ancestors
  • frame-src
  • img-src
  • script-src
  • style-src
  • font-src
Share Feedback
Page: /about/for-architects/security-architecture/content-security-policy
Section: About
Category *
Content Security Policy | Bloomreach Content Documentation