Configuring Content Security Policy (CSP) for Calcumate
Required allowlist
Directive
Domains to allow
Purpose
Example CSP header
Content-Security-Policy:
default-src 'self';
script-src 'self' https://*.calcumate.co;
connect-src 'self' https://*.calcumate.co https://optimize.calcumate.co https://r354ovsoac.execute-api.ap-southeast-2.amazonaws.com;
img-src 'self' data: https://*.calcumate.co https://calcumate-calculator-new-production.s3-ap-southeast-2.amazonaws.com https://calcumatev2-attachments-prod.s3-ap-southeast-2.amazonaws.com;
style-src 'self' 'unsafe-inline' https://*.calcumate.co;
frame-src 'self' https://*.calcumate.co;How to identify a CSP issue
Need help?
Last updated
Was this helpful?