On this page can set the Content Security Policy (CSP) and various other security HTTP headers.

External link

The CSP header comes with default policy

Content-Security-Policy: default-src 'self' data: 'unsafe-inline' 'unsafe-eval'

not visible or editable in the GUI. The Domains Allowed field values extend the policy with external source domain directives.

The Other Headers section allows adding miscellaneous headers, the format required is
Header-Name:header value #1;header value #2;
We set the following security headers by default:

Can add up to 20 additional headers in this section. This may be extended in future releases.

Add new attachment

Only authorized users are allowed to upload new attachments.

List of attachments

Kind Attachment Name Size Version Date Modified Author Change note
webinterfacecsp.jpg 109.0 kB 1 28-May-2021 10:56 Ada Csaba
« This page (revision-24) was last changed on 09-Jun-2021 05:15 by Ada Csaba
G’day (anonymous guest)
CrushFTP10 | What's New

Referenced by

JSPWiki v2.8.2