Skip to main content

Support stricter CSP in Featurebase.

Currently, the Featurebase SDK is built in such a way that it’s really hard to get it work in environments with strict CSP.


Original post:

We’ve integrated the Featurebase Changelog widget on our site by following this article: https://help.featurebase.app/en/articles/3449376-install-changelog-widget

However it’s falling foul of our CSP, and from what we can tell this seems to be because it’s injecting some inline styles.

We can overcome this by adding 'unsafe-inline'tostyle-src, but that’s said to be an anti-pattern.

What’s best practice when it comes to CSP for allowing the Changelog widget?

Status: Completed6 comments

Log in to comment and vote

Comments6

  • Robi Rohumaa changed status to Completed
    Team•

    Aug 3, 2024

    Pinned

    Featurebase now works in strict CSP environments!

    Learn more from this article: Using Featurebase with Content Security Policy

  • Robi Rohumaa changed status to In Progress
    Team•

    Aug 2, 2024

    Pinned

    After an initial investigation, it seems like supporting strict CSP setups is possible.

    It will require a bit of rewriting from our end, but I currently see a pretty nice path to getting the SDK working without any unsafe-inline values.

    Will report back if I have any more updates.

  • agyleOS

    •

    Mar 14, 2025

    Why the SDK stopped working when it cannot load fonts (because of CSP)?

  • -

    •

    Jul 30, 2024

    No worries and thanks for the advice, Robi.

    Also, it looks to me like this post is behind an auth wall of some sort. Would it be possible to make it publicly viewable so that others can benefit from it too? My guess is that CSP will be a common problem :)

    • Robi Rohumaa

      Team•

      Jul 31, 2024

      Opened the post up for everyone.

      I’ll look into what we can do to support this kind of setup. We’re probably going to have to make some pretty big changes, as our SDK relies very heavily on inline styling.

  • Robi Rohumaa

    Team•

    Jul 26, 2024

    Hey,

    Sadly, due to the way our SDK works, it’s really difficult to get it working in strict CSP contexts.

    If modifying the CSP to be less strict is not possible, I would advise using our API and creating your own changelog view in the app: https://docs.featurebase.app/changelogs#get-changelogs