web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / SharePoint2019 Content...
Power Automate
Unanswered

SharePoint2019 Content-Security-Policy  is not opening out of box popups and default icons ( default-src 'self and frame-ancestors 'none')

(0) ShareShare
ReportReport
Posted on by

Currently I am working on SharePoint 2019 Penetration Test issue fixing. I am not able to find the fix details for two Content-Security-Policy properties (frame-ancestors 'none' and object-src 'self') in SharePoint 2019 on premises.

 

a. Content-Security-Policy: default-src 'self';

I have received below error message after applying "default-src 'self'". in SharePoint 2019 web config.

<add name="Content-Security-Policy" value="default-src 'self';"/>

Error Message:

Refused to execute inline event handler because it violates the following Content Security Policy directive: "default-src 'self'". Either the 'unsafe-inline' keyword, a hash ('sha256-...'), or a nonce ('nonce-...') is required to enable inline execution. Note that hashes do not apply to event handlers, style attributes and javascript&colon; navigations unless the 'unsafe-hashes' keyword is present. Note also that 'script-src' was not explicitly set, so 'default-src' is used as a fallback.

 

b. Content-Security-Policy: frame-ancestors 'none'.

SharePoint Out Of Box popups are not working after applying "frame-ancestors 'none'". in SharePoint 2019 web config and getting the below error message.

<add name="Content-Security-Policy" value="frame-ancestors 'none';"/>

Error Message: Refused to frame 'http://sharepoint.testing.com/ because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'none'".

 

I am not able find the issue fix details in google. kindly someone help to provide at least Risk Acceptance MS Links to close this issue or provide if have a solution.

Categories:
I have the same question (0)

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Automate

#1
Michael E. Gernaey Profile Picture

Michael E. Gernaey 522 Super User 2025 Season 2

#2
Tomac Profile Picture

Tomac 364 Moderator

#3
abm abm Profile Picture

abm abm 243 Most Valuable Professional

Last 30 days Overall leaderboard