Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

How do I allow the Jira Service Widget with CSP without using unsafe-inline?

Kevin Johnson
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 26, 2024

I am trying to use the Service Management Widget (Contact Us button) on our websites but our content-security-policy (CSP) is blocking it. The only way to make this work is with setting the CSP with:

style-src 'self' 'unsafe-inline';

Is there another option to make this work? We will get flagged by security/pen tests if I were to set unsafe-inline.

Widget documentation: 

https://support.atlassian.com/jira-service-management-cloud/docs/embed-a-widget-onto-a-web-page/

0 answers

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
TAGS
AUG Leaders

Atlassian Community Events