Skip to main content
Jahia Store
EN

Content Security Policy

supported
Download 2.5.0

Information

Module ID
content-security-policy
Group ID
org.jahia.modules
Status
supported
Category
Security
Author
JSG
Developer website
http://www.jahia.com
Requires Jahia
8.1.8.0
Updated
2026-07-09
Source
scm:git:git@github.com:Jahia/content-security-policy.git
Tags
  • security

The purpose of this module is to allow the definition of a Content Security Policy for a website inside Digital Experience Manager. For more information about the Content Security Policy, please refer to this URL: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy

Screenshots

Versions

Improvements

  • Generate a nonce for every script tag
  • Introduced the ability to define a customer report URI at the site level
  • Re-introduced page-level content security policy
  • Added report-to instructions to the Content-Security-Policy and the Content-Security-Policy-Report-Only headers
Requires Jahia 8.1.8.0Updated 2025-10-14
  • Updated jahia-depends property to have more accurate dependencies
Requires Jahia 8.0.1.0Updated 2023-03-24
  • Added nonce injection mechanism
Requires Jahia 8.0.1.0Updated 2022-11-15
  • Fixed reporting issue when Jahia is deployed under non-root webcontext
Requires Jahia 8.0.1.0Updated 2022-03-11
  • Improved the protection of the Actions against security threat
Requires Jahia 8.0.1.0Updated 2020-09-04
  • New release compatible with Jahia 8
Requires Jahia 8.0.0.0Updated 2020-05-18
Requires Jahia 7.2.3.1Updated 2019-04-17
Requires Jahia 7.2.3.1Updated 2019-04-03