Support stricter CSP in Featurebase.

Currently, the Featurebase SDK is built in such a way that it’s really hard to get it work in environments with strict CSP.


Original post:

We’ve integrated the Featurebase Changelog widget on our site by following this article: https://help.featurebase.app/en/articles/3449376-install-changelog-widget

However it’s falling foul of our CSP, and from what we can tell this seems to be because it’s injecting some inline styles.

We can overcome this by adding 'unsafe-inline'tostyle-src, but that’s said to be an anti-pattern.

What’s best practice when it comes to CSP for allowing the Changelog widget?

Post type
-
What part?
-

Please authenticate to join the conversation.

Upvoters
Status

Completed

Board

Feedback & Roadmaps

Date

Over 1 year ago

Author

-

Subscribe to post

Get notified by email when there are changes.