web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Pages / Power Pages : Setting ...
Power Pages
Unanswered

Power Pages : Setting Content Security Policy Headers

(1) ShareShare
ReportReport
Posted on by 20
Hi Team,
 
We have Power Pages website and as per security scan we need to set the CSP policy , I have added few directives for CSP but security scan still shows following directives are missing

default-src
code-injection-objective
form-action-objective
reporting-objective

Let me know if you have any inputs regarding the same.
 
Regards
Categories:
I have the same question (0)
  • Michael E. Gernaey Profile Picture
    53,325 Super User 2025 Season 2 on at
    Hi,
     
    I'd have to see exactly what you set. It should have covered these. I am going to assume you synced etc?
  • vkartikiyer Profile Picture
    20 on at
    Hi FLMike ,
     
    Thanks for response.
    I am able to set default-src and other directives , only issue right now script-src tag.
    Following is the setting for CSP

    default-src https: 'unsafe-inline';font-src https: 'unsafe-inline';img-src https: 'unsafe-inline';style-src https: 'unsafe-inline';form-action https: 'unsafe-inline';script-src https: 'nonce' 'unsafe-inline';
     
    script-src tag is not allowing eval function to work without 'unsafe-eval' tag which is highlighted as security issue
    Also , we have inline action which is failing because of script-src settings
    Following is the snapshot

    Without 'unsafe-eval' tag


    Inline event Handler issue with script-src tag

     
     
    Also in Advance setting I don't see any tag for following directives which is reported as security issue
    code-injection-objective
    reporting-objective
     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Pages

#1
Jerry-IN Profile Picture

Jerry-IN 71

#2
Fubar Profile Picture

Fubar 62 Super User 2025 Season 2

#3
sannavajjala87 Profile Picture

sannavajjala87 31

Last 30 days Overall leaderboard