legacy-knowledge-base
公開されました Jun. 30, 2025

Is there a release date for implementing the Content Security Policy (CSP) at Liferay?

投稿者

Rishabh Agrawal

knowledge-article-header-disclaimer-how-to

knowledge-article-header-disclaimer

legacy-article

learn-legacy-article-disclaimer-text

Issue

  1. If CSP is in beta mode, how is Liferay protecting its system from vulnerability?
  2. Is there a timescale for when the CSP will be fully deployed in the portal?
  3. Once the CSP has been successfully implemented, can a fix be provided in the existing versions of DXP?

Environment

  • Liferay DXP [all versions]

Resolution

  • CSP is just an additional layer of protection. There are several other layers that can be applied according to the nature of the functionality that wants to be protected.
  • If the concern is regarding the missing CSP and Missing Secure Headers, then the missing CSP header itself is not considered a vulnerability.
  • There are certain directives that are planned to be implemented within 2025 Q1 and 2025 Q2. Also, the beta flag of CSP is planned to move to the released flag in milestone 2, which means the 2025 Q3 release.
  • If the fix of the CSP header is needed, it will be implemented as a new feature in the portal and cannot be backported in the older versions. Hence, the DXP version needs to be upgraded to use the feature.

Additional Information

did-this-article-resolve-your-issue

legacy-knowledge-base