Content Security Policies
The Content Security Policy (CSP) is a set of directives that inform the user's browser of locations from which an application is allowed to load resources. These locations are provided in the form of URL schemes, including the use of an asterisk (*) to represent all URLs. Each directive governs a specific resource type that affects what is displayed in a browser. Collectively, the directives are sent to the client in the Content-Security-Policy HTTP header. Each browser type and version obey as much of the policy as they can. If a browser does not understand a directive, it is ignored; otherwise it is explicitly followed.
To access the Content Security Policies in an application, do one of the following actions:
-
Specify the Content Security Policy on the Application form.
-
In the Designer Studio header, click
. -
On the Application form, click the Integration & security tab.
-
In the Policy name field, press the Down Arrow key, and then select the name of a content security policy.
-
To enforce the policy instead of reporting it only, click Reject and report.
- Click Save.
-
-
Use the Application Explorer to list the Content Security Policies in your application.
-
Use the Records Explorer to list all the Content Security Policies that are available to you.
Content Security Policy rules are instances of the Rule-Access-CSP class. They belong to the Security category.