Oracle JDeveloper (MOSC)

MOSC Banner

How to set Content Security Policy in an ADF application.

in Oracle JDeveloper (MOSC) 3 commentsAnswered ✓

Got feedback from security team that ADF application should have CSP and I google to understand about the same.

Came across with an article from oracle which says 'Oracle recommendation with regards to the response header "Context-Security-Policy" is to add unsafe-eval and unsafe-inline to CSP headers.'

I have 2 questions where I need community help regarding the same.

  1. Adding unsafe-eval and unsafe-inline is it helpful as CSP.
  2. How exactly CSP can be defined in an ADF application.

ADF : 12.2.1.4 , Weblogic server 12c

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center