Hi, Does anyone know if it's possible to set the C...
# all-things-deployment
f
Hi, Does anyone know if it's possible to set the Content-Security-Policy headers in the datahub front-end. We want to limit the posiblilties for XSS.
r
@square-jordan-23985 might be able to speak to this!
p
@fast-vr-89529 Did you maybe find an answer to set the CSP headers?
f
No I did set the env variable for secure cookies. AUTH_COOKIE_SECURE. Maybe @orange-night-91387 can still help us?
o
Play supports doing this through configuration so it is technically possible by mounting a custom application.conf file to your pod/container: https://www.playframework.com/documentation/2.9.x/CspFilter#Enabling-Through-Configuration We do have a ticket to have top level support for this so that it doesn’t require as much effort, but it is currently on the backlog and has not been prioritized