on 2024 Sep 26 9:51 PM
Dear SAP,
We are planning to integrate our Storefront with a third party service, which requires to be whitelisted in a Content-Security-Policy (CSP) in order to successfully work, but I am not sure how and where to create it.
Any ideas?
Thanks in advance!
Request clarification before answering.
Hello there!
The Content-Security-Policy has different approaches based on the Storefront you are running: For the Accelerator Storefront, it is configured through the property "xss.filter.header.Content-Security-Policy" in the affected endpoint aspect. More information in our documentations:
For the Composable Storefront you need to do it through an HTTP Response Header Set. The KBA 3334671 - Response Header set X-Frame-Options to deny - SAP Commerce Cloud is for a specific scenario, but in its resolution it explains how the Response Header with CSP should be configured:
Therefore, kindly create a response header with the desired configuration similar to the above one and assign it to your Composable Storefront.
Kind Regards,
Wesley
SAP Support
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
User | Count |
---|---|
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.