<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Accept Hosted Iframe CSP configuration concern in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-Iframe-CSP-configuration-concern/m-p/94976#M58693</link>
    <description>&lt;P&gt;I am framing the payment form, it loads and I can pay, but I get some errors on console.&lt;BR /&gt;Before loading the communicator I get these CSP errors&lt;BR /&gt;Executing inline script violates the following Content Security Policy directive 'script-src 'self' 'nonce-lieBPojqMUimm78ud0fuIg==' blob: https://*.ads-twitter.com https://*.authorize.net https://*.bing.com https://*.ceros.com https://*.contentsquare.com https://*.contentsquare.net https://*.cookiereports.com https://*.doubleclick.net https://*.eloqua.com https://*.en25.com https://*.facebook.net https://*.google-analytics.com https://*.google.com https://*.googleadservices.com https://*.googletagmanager.com https://*.gstatic.com https://*.idio.episerver.net https://*.licdn.com https://*.linkedin.com https://*.optimizely.com https://*.storygize.com https://*.twitter.com https://*.visa.com https://*.youtube.com &lt;A href="https://api.company-target.com" target="_blank"&gt;https://api.company-target.com&lt;/A&gt; &lt;A href="https://cdn-assets-prod.s3.amazonaws.com" target="_blank"&gt;https://cdn-assets-prod.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://code.jquery.com" target="_blank"&gt;https://code.jquery.com&lt;/A&gt; &lt;A href="https://company-target.com" target="_blank"&gt;https://company-target.com&lt;/A&gt; &lt;A href="https://id.rlcdn.com" target="_blank"&gt;https://id.rlcdn.com&lt;/A&gt; &lt;A href="https://optimizely.s3.amazonaws.com" target="_blank"&gt;https://optimizely.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://rlcdn.com" target="_blank"&gt;https://rlcdn.com&lt;/A&gt; &lt;A href="https://s.company-target.com" target="_blank"&gt;https://s.company-target.com&lt;/A&gt; &lt;A href="https://scripts.demandbase.com" target="_blank"&gt;https://scripts.demandbase.com&lt;/A&gt; &lt;A href="https://segments.company-target.com" target="_blank"&gt;https://segments.company-target.com&lt;/A&gt; &lt;A href="https://storygize.com" target="_blank"&gt;https://storygize.com&lt;/A&gt; &lt;A href="https://tag-logger.demandbase.com" target="_blank"&gt;https://tag-logger.demandbase.com&lt;/A&gt; &lt;A href="https://tag.demandbase.com" target="_blank"&gt;https://tag.demandbase.com&lt;/A&gt; &lt;A href="https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator&lt;/A&gt;'. Either the 'unsafe-inline' keyword, a hash ('sha256-rQFcSQ+uPvBBS36Ebz2AA8DWF5LxdwuQKeLhxEfN+Ec='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.&lt;BR /&gt;Executing inline script violates the following Content Security Policy directive 'script-src 'self' 'nonce-lieBPojqMUimm78ud0fuIg==' blob: https://*.ads-twitter.com https://*.authorize.net https://*.bing.com https://*.ceros.com https://*.contentsquare.com https://*.contentsquare.net https://*.cookiereports.com https://*.doubleclick.net https://*.eloqua.com https://*.en25.com https://*.facebook.net https://*.google-analytics.com https://*.google.com https://*.googleadservices.com https://*.googletagmanager.com https://*.gstatic.com https://*.idio.episerver.net https://*.licdn.com https://*.linkedin.com https://*.optimizely.com https://*.storygize.com https://*.twitter.com https://*.visa.com https://*.youtube.com &lt;A href="https://api.company-target.com" target="_blank"&gt;https://api.company-target.com&lt;/A&gt; &lt;A href="https://cdn-assets-prod.s3.amazonaws.com" target="_blank"&gt;https://cdn-assets-prod.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://code.jquery.com" target="_blank"&gt;https://code.jquery.com&lt;/A&gt; &lt;A href="https://company-target.com" target="_blank"&gt;https://company-target.com&lt;/A&gt; &lt;A href="https://id.rlcdn.com" target="_blank"&gt;https://id.rlcdn.com&lt;/A&gt; &lt;A href="https://optimizely.s3.amazonaws.com" target="_blank"&gt;https://optimizely.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://rlcdn.com" target="_blank"&gt;https://rlcdn.com&lt;/A&gt; &lt;A href="https://s.company-target.com" target="_blank"&gt;https://s.company-target.com&lt;/A&gt; &lt;A href="https://scripts.demandbase.com" target="_blank"&gt;https://scripts.demandbase.com&lt;/A&gt; &lt;A href="https://segments.company-target.com" target="_blank"&gt;https://segments.company-target.com&lt;/A&gt; &lt;A href="https://storygize.com" target="_blank"&gt;https://storygize.com&lt;/A&gt; &lt;A href="https://tag-logger.demandbase.com" target="_blank"&gt;https://tag-logger.demandbase.com&lt;/A&gt; &lt;A href="https://tag.demandbase.com" target="_blank"&gt;https://tag.demandbase.com&lt;/A&gt; &lt;A href="https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator&lt;/A&gt;'. Either the 'unsafe-inline' keyword, a hash ('sha256-rQFcSQ+uPvBBS36Ebz2AA8DWF5LxdwuQKeLhxEfN+Ec='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.&lt;/P&gt;&lt;P&gt;After I successfully do the payment I get these errors&lt;BR /&gt;Applying inline style violates the following Content Security Policy directive 'style-src 'self' 'nonce-lieBPojqMUimm78ud0fuIg==' https://*.authorize.net https://*.ceros.com https://*.eloqua.com https://*.google.com https://*.gsatic.com https://*.licdn.com https://*.optimizely.com https://*.visa.com &lt;A href="https://fonts.googleapis.com" target="_blank"&gt;https://fonts.googleapis.com&lt;/A&gt; &lt;A href="https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator&lt;/A&gt;'. Either the 'unsafe-inline' keyword, a hash ('sha256-0EZqoz+oBhx7gF4nvY2bSqoGyy4zLjNF+SDQXGp/ZrY='), or a nonce ('nonce-...') is required to enable inline execution. Note that hashes do not apply to event handlers, style attributes and javascript&amp;amp;colon; navigations unless the 'unsafe-hashes' keyword is present. The action has been blocked.&lt;BR /&gt;Applying inline style violates the following Content Security Policy directive 'style-src 'self' 'nonce-lieBPojqMUimm78ud0fuIg==' https://*.authorize.net https://*.ceros.com https://*.eloqua.com https://*.google.com https://*.gsatic.com https://*.licdn.com https://*.optimizely.com https://*.visa.com &lt;A href="https://fonts.googleapis.com" target="_blank"&gt;https://fonts.googleapis.com&lt;/A&gt; &lt;A href="https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator&lt;/A&gt;'. Either the 'unsafe-inline' keyword, a hash ('sha256-0EZqoz+oBhx7gF4nvY2bSqoGyy4zLjNF+SDQXGp/ZrY='), or a nonce ('nonce-...') is required to enable inline execution. Note that hashes do not apply to event handlers, style attributes and javascript&amp;amp;colon; navigations unless the 'unsafe-hashes' keyword is present. The action has been blocked.&lt;BR /&gt;Framing '&lt;A href="https://anetnahuel.master.visitstaging.org/" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/&lt;/A&gt;' violates the following Content Security Policy directive: "frame-src 'self' truclinicapp: js.stripe.com cdn.visitnow.org lib.paymentjs.firstdata.com api.convergepay.com api.demo.convergepay.com test.authorize.net accept.authorize.net". The request has been blocked.&lt;/P&gt;&lt;P&gt;My application lives on the domain 'patient.master.visitstaging.org', my communicator comes from the domain 'master.visitstaging.org'.&lt;/P&gt;&lt;P&gt;How should i define my CSP rules on 'patient.master.visitstaging.org' to frame correctly the iframe?&lt;BR /&gt;Same question on the communicator endpoint response so it can be used inside the iframe and it can communicate with my main application?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Mar 2026 21:13:20 GMT</pubDate>
    <dc:creator>NScarlatoTdoc</dc:creator>
    <dc:date>2026-03-10T21:13:20Z</dc:date>
    <item>
      <title>Accept Hosted Iframe CSP configuration concern</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-Iframe-CSP-configuration-concern/m-p/94976#M58693</link>
      <description>&lt;P&gt;I am framing the payment form, it loads and I can pay, but I get some errors on console.&lt;BR /&gt;Before loading the communicator I get these CSP errors&lt;BR /&gt;Executing inline script violates the following Content Security Policy directive 'script-src 'self' 'nonce-lieBPojqMUimm78ud0fuIg==' blob: https://*.ads-twitter.com https://*.authorize.net https://*.bing.com https://*.ceros.com https://*.contentsquare.com https://*.contentsquare.net https://*.cookiereports.com https://*.doubleclick.net https://*.eloqua.com https://*.en25.com https://*.facebook.net https://*.google-analytics.com https://*.google.com https://*.googleadservices.com https://*.googletagmanager.com https://*.gstatic.com https://*.idio.episerver.net https://*.licdn.com https://*.linkedin.com https://*.optimizely.com https://*.storygize.com https://*.twitter.com https://*.visa.com https://*.youtube.com &lt;A href="https://api.company-target.com" target="_blank"&gt;https://api.company-target.com&lt;/A&gt; &lt;A href="https://cdn-assets-prod.s3.amazonaws.com" target="_blank"&gt;https://cdn-assets-prod.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://code.jquery.com" target="_blank"&gt;https://code.jquery.com&lt;/A&gt; &lt;A href="https://company-target.com" target="_blank"&gt;https://company-target.com&lt;/A&gt; &lt;A href="https://id.rlcdn.com" target="_blank"&gt;https://id.rlcdn.com&lt;/A&gt; &lt;A href="https://optimizely.s3.amazonaws.com" target="_blank"&gt;https://optimizely.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://rlcdn.com" target="_blank"&gt;https://rlcdn.com&lt;/A&gt; &lt;A href="https://s.company-target.com" target="_blank"&gt;https://s.company-target.com&lt;/A&gt; &lt;A href="https://scripts.demandbase.com" target="_blank"&gt;https://scripts.demandbase.com&lt;/A&gt; &lt;A href="https://segments.company-target.com" target="_blank"&gt;https://segments.company-target.com&lt;/A&gt; &lt;A href="https://storygize.com" target="_blank"&gt;https://storygize.com&lt;/A&gt; &lt;A href="https://tag-logger.demandbase.com" target="_blank"&gt;https://tag-logger.demandbase.com&lt;/A&gt; &lt;A href="https://tag.demandbase.com" target="_blank"&gt;https://tag.demandbase.com&lt;/A&gt; &lt;A href="https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator&lt;/A&gt;'. Either the 'unsafe-inline' keyword, a hash ('sha256-rQFcSQ+uPvBBS36Ebz2AA8DWF5LxdwuQKeLhxEfN+Ec='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.&lt;BR /&gt;Executing inline script violates the following Content Security Policy directive 'script-src 'self' 'nonce-lieBPojqMUimm78ud0fuIg==' blob: https://*.ads-twitter.com https://*.authorize.net https://*.bing.com https://*.ceros.com https://*.contentsquare.com https://*.contentsquare.net https://*.cookiereports.com https://*.doubleclick.net https://*.eloqua.com https://*.en25.com https://*.facebook.net https://*.google-analytics.com https://*.google.com https://*.googleadservices.com https://*.googletagmanager.com https://*.gstatic.com https://*.idio.episerver.net https://*.licdn.com https://*.linkedin.com https://*.optimizely.com https://*.storygize.com https://*.twitter.com https://*.visa.com https://*.youtube.com &lt;A href="https://api.company-target.com" target="_blank"&gt;https://api.company-target.com&lt;/A&gt; &lt;A href="https://cdn-assets-prod.s3.amazonaws.com" target="_blank"&gt;https://cdn-assets-prod.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://code.jquery.com" target="_blank"&gt;https://code.jquery.com&lt;/A&gt; &lt;A href="https://company-target.com" target="_blank"&gt;https://company-target.com&lt;/A&gt; &lt;A href="https://id.rlcdn.com" target="_blank"&gt;https://id.rlcdn.com&lt;/A&gt; &lt;A href="https://optimizely.s3.amazonaws.com" target="_blank"&gt;https://optimizely.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://rlcdn.com" target="_blank"&gt;https://rlcdn.com&lt;/A&gt; &lt;A href="https://s.company-target.com" target="_blank"&gt;https://s.company-target.com&lt;/A&gt; &lt;A href="https://scripts.demandbase.com" target="_blank"&gt;https://scripts.demandbase.com&lt;/A&gt; &lt;A href="https://segments.company-target.com" target="_blank"&gt;https://segments.company-target.com&lt;/A&gt; &lt;A href="https://storygize.com" target="_blank"&gt;https://storygize.com&lt;/A&gt; &lt;A href="https://tag-logger.demandbase.com" target="_blank"&gt;https://tag-logger.demandbase.com&lt;/A&gt; &lt;A href="https://tag.demandbase.com" target="_blank"&gt;https://tag.demandbase.com&lt;/A&gt; &lt;A href="https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator&lt;/A&gt;'. Either the 'unsafe-inline' keyword, a hash ('sha256-rQFcSQ+uPvBBS36Ebz2AA8DWF5LxdwuQKeLhxEfN+Ec='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.&lt;/P&gt;&lt;P&gt;After I successfully do the payment I get these errors&lt;BR /&gt;Applying inline style violates the following Content Security Policy directive 'style-src 'self' 'nonce-lieBPojqMUimm78ud0fuIg==' https://*.authorize.net https://*.ceros.com https://*.eloqua.com https://*.google.com https://*.gsatic.com https://*.licdn.com https://*.optimizely.com https://*.visa.com &lt;A href="https://fonts.googleapis.com" target="_blank"&gt;https://fonts.googleapis.com&lt;/A&gt; &lt;A href="https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator&lt;/A&gt;'. Either the 'unsafe-inline' keyword, a hash ('sha256-0EZqoz+oBhx7gF4nvY2bSqoGyy4zLjNF+SDQXGp/ZrY='), or a nonce ('nonce-...') is required to enable inline execution. Note that hashes do not apply to event handlers, style attributes and javascript&amp;amp;colon; navigations unless the 'unsafe-hashes' keyword is present. The action has been blocked.&lt;BR /&gt;Applying inline style violates the following Content Security Policy directive 'style-src 'self' 'nonce-lieBPojqMUimm78ud0fuIg==' https://*.authorize.net https://*.ceros.com https://*.eloqua.com https://*.google.com https://*.gsatic.com https://*.licdn.com https://*.optimizely.com https://*.visa.com &lt;A href="https://fonts.googleapis.com" target="_blank"&gt;https://fonts.googleapis.com&lt;/A&gt; &lt;A href="https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/authorize-net/9fe3ed57-950d-4a84-aa09-82b1ca7226b8/communicator&lt;/A&gt;'. Either the 'unsafe-inline' keyword, a hash ('sha256-0EZqoz+oBhx7gF4nvY2bSqoGyy4zLjNF+SDQXGp/ZrY='), or a nonce ('nonce-...') is required to enable inline execution. Note that hashes do not apply to event handlers, style attributes and javascript&amp;amp;colon; navigations unless the 'unsafe-hashes' keyword is present. The action has been blocked.&lt;BR /&gt;Framing '&lt;A href="https://anetnahuel.master.visitstaging.org/" target="_blank"&gt;https://anetnahuel.master.visitstaging.org/&lt;/A&gt;' violates the following Content Security Policy directive: "frame-src 'self' truclinicapp: js.stripe.com cdn.visitnow.org lib.paymentjs.firstdata.com api.convergepay.com api.demo.convergepay.com test.authorize.net accept.authorize.net". The request has been blocked.&lt;/P&gt;&lt;P&gt;My application lives on the domain 'patient.master.visitstaging.org', my communicator comes from the domain 'master.visitstaging.org'.&lt;/P&gt;&lt;P&gt;How should i define my CSP rules on 'patient.master.visitstaging.org' to frame correctly the iframe?&lt;BR /&gt;Same question on the communicator endpoint response so it can be used inside the iframe and it can communicate with my main application?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2026 21:13:20 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-Iframe-CSP-configuration-concern/m-p/94976#M58693</guid>
      <dc:creator>NScarlatoTdoc</dc:creator>
      <dc:date>2026-03-10T21:13:20Z</dc:date>
    </item>
  </channel>
</rss>

