What is Content Security Protocol?
In the simplest terms, a Content Security Protocol (CSP) is an HTTP response header that informs the browser what it is allowed to do. You control various security aspects through the use of directives which are assigned permissions. Using a strict CSP helps you prevent Cross Site Scripting (XSS) attacks from malicious users. This article explains more about CSP and how to apply a Content Security Protocol header to your site.
Directives that Cookiebot Supports
Cookiebot supports the following directives (your organization's security protocol requirements might be different):
A nonce (a value that is only used once) should be dynamically generated and applied to script tags on each page load. Users may also opt to use a hash value, please see this documentation on how to apply your script-src value.
An example CSP implementation using the directives above in a META tag would look this:
script-src 'nonce-XXXXXXXXXX' 'strict-dynamic';
style-src 'self' 'unsafe-inline';
connect-src 'self' https://consentcdn.cookiebot.com;
frame-src 'self' https://consentcdn.cookiebot.com;
img-src 'self' data:;
Evaluating Your Content Security Protocol
We have evaluated our support against CSP Version 3 using Google's CSP Evaluator. Our CSP support provides safe evaluation for all the directives indicated above. This support will be validated for each change we make.
Cookiebot’s CSP support is not fully compatible with Automatic Cookie Blocking. If your site contains script tags without a src attribute, we cannot determine the policy to apply to the element and the script will run regardless of the CSP applied. Please fully test your site for functionality before trying to use Automatic Cookie Blocking with a CSP header.