<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94735#M58587</link>
    <description>&lt;P&gt;UPDATE:&amp;nbsp;I talked with Authorize.Net Support, and they have acknowledged the issue and told me they are working on a fix. However, they were unable to provide a timeline for resolution.&lt;/P&gt;</description>
    <pubDate>Fri, 19 Dec 2025 16:06:41 GMT</pubDate>
    <dc:creator>aacampillo</dc:creator>
    <dc:date>2025-12-19T16:06:41Z</dc:date>
    <item>
      <title>Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94677#M58559</link>
      <description>&lt;P&gt;Urgent Sandbox issue. Our product has been successfully using the Accept Hosted payment method for years now where we embed the form in an iFrame. Recently the Chrome and Edge browsers started enforcing a content security policy that is blocking the action of the hosted form. Is anyone else experiencing this issue? We can't change anything in the embedded form provided by Authorize.Net to avoid the CSP issues, so we are helpless.&lt;/P&gt;&lt;P&gt;Error from browser console:&lt;/P&gt;&lt;P&gt;Executing inline script violates the following Content Security Policy directive 'script-src 'self' 'nonce-JPULaiHJBUucGA4TtPGSGA==' blob: https://*.ads-twitter.com https://*.authorize.net https://*.bing.com https://*.ceros.com https://*.contentsquare.com https://*.contentsquare.net https://*.cookiereports.com https://*.doubleclick.net https://*.eloqua.com https://*.en25.com https://*.facebook.net https://*.google-analytics.com https://*.google.com https://*.googleadservices.com https://*.googletagmanager.com https://*.gstatic.com https://*.idio.episerver.net https://*.licdn.com https://*.linkedin.com https://*.optimizely.com https://*.storygize.com https://*.twitter.com https://*.visa.com https://*.youtube.com &lt;A href="https://api.company-target.com" target="_blank"&gt;https://api.company-target.com&lt;/A&gt; &lt;A href="https://cdn-assets-prod.s3.amazonaws.com" target="_blank"&gt;https://cdn-assets-prod.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://code.jquery.com" target="_blank"&gt;https://code.jquery.com&lt;/A&gt; &lt;A href="https://company-target.com" target="_blank"&gt;https://company-target.com&lt;/A&gt; &lt;A href="https://id.rlcdn.com" target="_blank"&gt;https://id.rlcdn.com&lt;/A&gt; &lt;A href="https://optimizely.s3.amazonaws.com" target="_blank"&gt;https://optimizely.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://rlcdn.com" target="_blank"&gt;https://rlcdn.com&lt;/A&gt; &lt;A href="https://s.company-target.com" target="_blank"&gt;https://s.company-target.com&lt;/A&gt; &lt;A href="https://scripts.demandbase.com" target="_blank"&gt;https://scripts.demandbase.com&lt;/A&gt; &lt;A href="https://segments.company-target.com" target="_blank"&gt;https://segments.company-target.com&lt;/A&gt; &lt;A href="https://storygize.com" target="_blank"&gt;https://storygize.com&lt;/A&gt; &lt;A href="https://tag-logger.demandbase.com" target="_blank"&gt;https://tag-logger.demandbase.com&lt;/A&gt; &lt;A href="https://tag.demandbase.com" target="_blank"&gt;https://tag.demandbase.com&lt;/A&gt; https://&amp;lt;domain&amp;nbsp;and path&amp;gt;/IFrameCommunicator.html'. Either the 'unsafe-inline' keyword, a hash ('sha256-rQFcSQ+uPvBBS36Ebz2AA8DWF5LxdwuQKeLhxEfN+Ec='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.&lt;/P&gt;&lt;P&gt;This is ONLY happening in the sandbox environments, not in production environments. However, our company replies on these sandbox environments to test and support hundreds of customers, but now we can no longer use them.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Dec 2025 17:35:39 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94677#M58559</guid>
      <dc:creator>aacampillo</dc:creator>
      <dc:date>2025-12-07T17:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94735#M58587</link>
      <description>&lt;P&gt;UPDATE:&amp;nbsp;I talked with Authorize.Net Support, and they have acknowledged the issue and told me they are working on a fix. However, they were unable to provide a timeline for resolution.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 16:06:41 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94735#M58587</guid>
      <dc:creator>aacampillo</dc:creator>
      <dc:date>2025-12-19T16:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/95009#M58710</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/33346"&gt;@aacampillo&lt;/a&gt;&amp;nbsp;have you received any update on the upcoming fix? We continue to see the issue as of today.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 18:23:33 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/95009#M58710</guid>
      <dc:creator>NAntiman</dc:creator>
      <dc:date>2026-03-23T18:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/95011#M58712</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/71584"&gt;@NAntiman&lt;/a&gt;&amp;nbsp;No update yet. I will reach out to them again now that it's been a few months.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 21:17:37 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/95011#M58712</guid>
      <dc:creator>aacampillo</dc:creator>
      <dc:date>2026-03-23T21:17:37Z</dc:date>
    </item>
  </channel>
</rss>

