Content-Security-Policy Header Integration
How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!
While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.
Legacy Article
You are viewing an article from our legacy "FastTrack"
publication program, made available for informational purposes. Articles
in this program were published without a requirement for independent
editing or verification and are provided"as is" without
guarantee.
Before using any information from this article, independently verify its
suitability for your situation and project.
Issue
- How can a CSP (content security policy) HTTP header that enables only specific external resources to be loaded in the frontend be implemented?

Resolution
- CSP is not currently supported by Liferay at the product level.
- Liferay DXP and its predecessor, Liferay Portal EE, were not designed with the expectation that an inline or eval-restricting CSP may be applied at runtime. As a result, Liferay products are not compatible with the CSP.
- However, there is the possibility to apply third-party solutions or implement CSP in a custom way via webserver or theme.
- A Feature Request has been raised for this matter already and there is an ongoing discussion about it at the moment, but the primary product team still needs to agree to this feature. They will basically need to rewrite a lot of the frontend JS code and this will take some time.
Did this article resolve your issue ?