Skip to main content
Announcements
Get Ready. A New Qlik Learning Experience is Coming February 17! LEARN MORE
cancel
Showing results for 
Search instead for 
Did you mean: 
_rohitgharat
Creator
Creator

Not able to apply Content Security Policy on Qliksense Enterprise version

Hi,
We are trying to apply Content security policy on Qliksense Enterprise version for our headers:
QMC>>Virtual Proxies>>Advanced>> Additional Response headers
We tried all the below syntax for Content security policy:
Content-Security-Policy: default-src 'self'; img-src *;
Content-Security-Policy:
default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';base-uri 'self';form-action 'self'
 But when we apply the above syntax for CSP, Qliksense login page doesn't load properly and the subsequent pages for dashboards turns blank.
Kindly suggest how can we implement CSP in Qliksense Enterprise version?.
 
Thanks in Advance.
Regards,
Rohit Gharat
1 Solution
2 Replies
nilesh007
Partner - Creator
Partner - Creator

Hi Community,

In Qlik sense enterprise, according to VAPT report there are some missing security headers which needs to be implemented. We are facing issue while adding the below security header in the virtual proxy.
--> Content-Security-Policy: default-src 'self'
After implementing it we are unable to access qlik getting black/grey screen.

Articles followed:

https://community.qlik.com/t5/Official-Support-Articles/Qlik-Sense-Enterprise-on-Windows-Securing-an....

How to determine string policy for Content Securit... - Qlik Community - 1715491