Support stricter CSP in Featurebase.
Currently, the Featurebase SDK is built in such a way that it’s really hard to get it work in environments with strict CSP.
Original post:
We’ve integrated the Featurebase Changelog widget on our site by following this article: https://help.featurebase.app/en/articles/3449376-install-changelog-widget
However it’s falling foul of our CSP, and from what we can tell this seems to be because it’s injecting some inline styles.
We can overcome this by adding 'unsafe-inline'tostyle-src, but that’s said to be an anti-pattern.
What’s best practice when it comes to CSP for allowing the Changelog widget?
Log in to comment and vote
Comments6
Aug 3, 2024
PinnedFeaturebase now works in strict CSP environments!
Learn more from this article: Using Featurebase with Content Security Policy
Aug 2, 2024
PinnedAfter an initial investigation, it seems like supporting strict CSP setups is possible.
It will require a bit of rewriting from our end, but I currently see a pretty nice path to getting the SDK working without any
unsafe-inlinevalues.Will report back if I have any more updates.
agyleOS
Mar 14, 2025
Why the SDK stopped working when it cannot load fonts (because of CSP)?
-
Jul 30, 2024
No worries and thanks for the advice, Robi.
Also, it looks to me like this post is behind an auth wall of some sort. Would it be possible to make it publicly viewable so that others can benefit from it too? My guess is that CSP will be a common problem :)
Robi Rohumaa
Jul 31, 2024
Opened the post up for everyone.
I’ll look into what we can do to support this kind of setup. We’re probably going to have to make some pretty big changes, as our SDK relies very heavily on inline styling.
Robi Rohumaa
Jul 26, 2024
Hey,
Sadly, due to the way our SDK works, it’s really difficult to get it working in strict CSP contexts.
If modifying the CSP to be less strict is not possible, I would advise using our API and creating your own changelog view in the app: https://docs.featurebase.app/changelogs#get-changelogs