<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>[LF7.x] CSP compatibility</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121507365" />
  <subtitle>[LF7.x] CSP compatibility</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=121507365</id>
  <updated>2026-04-04T06:21:28Z</updated>
  <dc:date>2026-04-04T06:21:28Z</dc:date>
  <entry>
    <title>RE: [LF7.x] CSP compatibility</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121507786" />
    <author>
      <name>Zsigmond Rab</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121507786</id>
    <updated>2022-09-02T17:43:18Z</updated>
    <published>2022-09-02T17:43:17Z</published>
    <summary type="html">&lt;p&gt;Hi Tinfo,&lt;/p&gt;
&lt;p&gt;Making the portal CSP compliant is one of our next enhancements. You
  can watch the https://issues.liferay.com/browse/LPS-134060 ticket for updates.&lt;/p&gt;
&lt;p&gt;That is also planned to cover what to do with inline scripts and
  styles at a point.&lt;/p&gt;
&lt;p&gt;I personally appreciate if you can share any experiences, further
  needs that you think we should consider in the implementation. I mean,
  beyond what is needed to be implemented for being compliant with the standard.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Zsigmond&lt;/p&gt;</summary>
    <dc:creator>Zsigmond Rab</dc:creator>
    <dc:date>2022-09-02T17:43:17Z</dc:date>
  </entry>
  <entry>
    <title>[LF7.x] CSP compatibility</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121507364" />
    <author>
      <name>Tinfo Tinfo</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=121507364</id>
    <updated>2022-09-02T09:02:34Z</updated>
    <published>2022-09-02T09:02:34Z</published>
    <summary type="html">&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;is Liferay Portal CSP compliant?&lt;/p&gt;
&lt;p&gt;Actually if we try to add CSP directive&lt;/p&gt;
&lt;pre&gt;
&lt;code class="language-java"&gt;Content-Security-Policy: script-src 'self';&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;the portal loads with lots of errors in browser console like these:&lt;/p&gt;
&lt;pre&gt;
&lt;code class="language-java"&gt;Content Security Policy: The page's settings blocked the loading of a resource at inline (&amp;quot;script-src&amp;quot;)
Uncaught ReferenceError: Liferay is not defined
Uncaught ReferenceError: AUI is not defined&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We are missing something?&lt;/p&gt;
&lt;p&gt;Is there any plan in the future to make Liferay Portal CSP compliant
  by removing all inline script and style? &lt;/p&gt;</summary>
    <dc:creator>Tinfo Tinfo</dc:creator>
    <dc:date>2022-09-02T09:02:34Z</dc:date>
  </entry>
</feed>
