Main website
Government Drupal Developers NetworkCommunity

Security

CSP headers breaking our embedded maps: what's your policy?

Started by Liam Tremblay on · 54 views · 0 replies · 1 like

LT

Liam TremblayStarted the thread

Platform Engineer, Canadian Digital Service ·

After tightening our Content Security Policy, the embedded consultation maps on our planning pages stopped rendering. The console shows:

Refused to frame 'https://maps.example' because it violates the following
Content Security Policy directive: "frame-src 'self'".

Do you allow-list per page, or keep a global list of approved embed providers?

No replies yet

Be the first to help out. Even a pointer to the right docs is useful.

Join the conversation

GDDN is for people working on Drupal in government. Log in or apply to reply.