Legacy Knowledge Base
Published Jul. 2, 2025

Content-Security-Policy Header Integration

Written By

Kanchan Bisht

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

Legacy Article

You are viewing an article from our legacy "FastTrack" publication program, made available for informational purposes. Articles in this program were published without a requirement for independent editing or verification and are provided"as is" without guarantee.

Before using any information from this article, independently verify its suitability for your situation and project.

Issue

  • How can a CSP (content security policy) HTTP header that enables only specific external resources to be loaded in the frontend be implemented? Screenshot__139_.png

Environment

  • Liferay DXP 7.2

Resolution

  • CSP is not currently supported by Liferay at the product level.
  • Liferay DXP and its predecessor, Liferay Portal EE, were not designed with the expectation that an inline or eval-restricting CSP may be applied at runtime. As a result, Liferay products are not compatible with the CSP.
  • However, there is the possibility to apply third-party solutions or implement CSP in a custom way via webserver or theme.
  • A Feature Request has been raised for this matter already and there is an ongoing discussion about it at the moment, but the primary product team still needs to agree to this feature. They will basically need to rewrite a lot of the frontend JS code and this will take some time.

Additional Information

  • We have a different channel called "Global Service Team" in case of further assistance regarding customization.
  • Feature Request ticket, as noted in the Feature Request documentation, these tickets are requests to implement a new feature in future versions of Liferay, and it would be at our Product Team's discretion to determine the timeline of new features being added to Liferay. 
  • As the request progresses, it can be monitored and checked on. The status of the request will change to 'complete' if the Product Team approves it and the feature is implemented, after which a ticket can be submitted to seek a hotfix. In the meantime, one can follow the ticket and vote for this feature by clicking on 'Vote for this issue'.
  • Why certain Security Headers are not included in the HTTP Request and Response of Liferay DXP
Did this article resolve your issue ?

Legacy Knowledge Base