Do not input private or sensitive data. View Qlik Privacy & Cookie Policy.
Skip to main content

Announcements
Qlik and ServiceNow Partner to Bring Trusted Enterprise Context into AI-Powered Workflows. Learn More!
cancel
Showing results for 
Search instead for 
Did you mean: 
dobak
Partner - Contributor III
Partner - Contributor III

recommended policy for Content Security Policy

a customer of ours wants to setup Content Security Policy (CSP). i have learned that i can add that via Additional Response Headers in Qlik Sense QMC.

 

but i could not find any recommended policies for Qlik. does anyone have experience with this?

 

Labels (2)
1 Solution

Accepted Solutions
Jay_Brown
Support
Support

Hi @dobak , In general, Content-Security-Policy is not something that Qlik has recommendations for. This is more of an environment hardening issue.

As part of best-effort, I can point you to the most relevant articles and discussions about this as there is some good info in there:

  1. https://community.qlik.com/t5/Official-Support-Articles/What-is-CSP-Content-Security-Policy-and-How-... 
  2. https://community.qlik.com/t5/Official-Support-Articles/How-to-add-additional-response-headers-in-Ql... 
  3. https://community.qlik.com/t5/Security-Governance/Not-able-to-apply-Content-Security-Policy-on-Qliks... 
  4. https://community.qlik.com/t5/Official-Support-Articles/How-to-determine-string-policy-for-Content-S... 
  5. https://support.qlik.com/articles/000069349 

I will say that in the field, mistakes with this hardening can sometimes break access to the environment so it is recommended to fully research those implementations and test them in lower environments prior to deploying.

I hope that helps!

To help users find verified answers, please don't forget to mark a correct resolution or answer to your problem or question as correct.

View solution in original post

1 Reply
Jay_Brown
Support
Support

Hi @dobak , In general, Content-Security-Policy is not something that Qlik has recommendations for. This is more of an environment hardening issue.

As part of best-effort, I can point you to the most relevant articles and discussions about this as there is some good info in there:

  1. https://community.qlik.com/t5/Official-Support-Articles/What-is-CSP-Content-Security-Policy-and-How-... 
  2. https://community.qlik.com/t5/Official-Support-Articles/How-to-add-additional-response-headers-in-Ql... 
  3. https://community.qlik.com/t5/Security-Governance/Not-able-to-apply-Content-Security-Policy-on-Qliks... 
  4. https://community.qlik.com/t5/Official-Support-Articles/How-to-determine-string-policy-for-Content-S... 
  5. https://support.qlik.com/articles/000069349 

I will say that in the field, mistakes with this hardening can sometimes break access to the environment so it is recommended to fully research those implementations and test them in lower environments prior to deploying.

I hope that helps!

To help users find verified answers, please don't forget to mark a correct resolution or answer to your problem or question as correct.