<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/96011#M59221</link>
    <description>&lt;P&gt;We’ve seen similar differences between sandbox and production with hosted payment integrations. The fact that the same iframe works in production but gets blocked in the sandbox makes it seem more like an environment-side CSP change than an integration issue. It would be helpful to know whether the sandbox policy has since been updated or if there’s a recommended workaround for testing&lt;A href="https://locksmithvineland.com/" target="_self"&gt;.&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 19 Sep 2026 19:10:08 GMT</pubDate>
    <dc:creator>edwardharry</dc:creator>
    <dc:date>2026-09-19T19:10:08Z</dc:date>
    <item>
      <title>Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94677#M58559</link>
      <description>&lt;P&gt;Urgent Sandbox issue. Our product has been successfully using the Accept Hosted payment method for years now where we embed the form in an iFrame. Recently the Chrome and Edge browsers started enforcing a content security policy that is blocking the action of the hosted form. Is anyone else experiencing this issue? We can't change anything in the embedded form provided by Authorize.Net to avoid the CSP issues, so we are helpless.&lt;/P&gt;&lt;P&gt;Error from browser console:&lt;/P&gt;&lt;P&gt;Executing inline script violates the following Content Security Policy directive 'script-src 'self' 'nonce-JPULaiHJBUucGA4TtPGSGA==' blob: https://*.ads-twitter.com https://*.authorize.net https://*.bing.com https://*.ceros.com https://*.contentsquare.com https://*.contentsquare.net https://*.cookiereports.com https://*.doubleclick.net https://*.eloqua.com https://*.en25.com https://*.facebook.net https://*.google-analytics.com https://*.google.com https://*.googleadservices.com https://*.googletagmanager.com https://*.gstatic.com https://*.idio.episerver.net https://*.licdn.com https://*.linkedin.com https://*.optimizely.com https://*.storygize.com https://*.twitter.com https://*.visa.com https://*.youtube.com &lt;A href="https://api.company-target.com" target="_blank"&gt;https://api.company-target.com&lt;/A&gt; &lt;A href="https://cdn-assets-prod.s3.amazonaws.com" target="_blank"&gt;https://cdn-assets-prod.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://code.jquery.com" target="_blank"&gt;https://code.jquery.com&lt;/A&gt; &lt;A href="https://company-target.com" target="_blank"&gt;https://company-target.com&lt;/A&gt; &lt;A href="https://id.rlcdn.com" target="_blank"&gt;https://id.rlcdn.com&lt;/A&gt; &lt;A href="https://optimizely.s3.amazonaws.com" target="_blank"&gt;https://optimizely.s3.amazonaws.com&lt;/A&gt; &lt;A href="https://rlcdn.com" target="_blank"&gt;https://rlcdn.com&lt;/A&gt; &lt;A href="https://s.company-target.com" target="_blank"&gt;https://s.company-target.com&lt;/A&gt; &lt;A href="https://scripts.demandbase.com" target="_blank"&gt;https://scripts.demandbase.com&lt;/A&gt; &lt;A href="https://segments.company-target.com" target="_blank"&gt;https://segments.company-target.com&lt;/A&gt; &lt;A href="https://storygize.com" target="_blank"&gt;https://storygize.com&lt;/A&gt; &lt;A href="https://tag-logger.demandbase.com" target="_blank"&gt;https://tag-logger.demandbase.com&lt;/A&gt; &lt;A href="https://tag.demandbase.com" target="_blank"&gt;https://tag.demandbase.com&lt;/A&gt; https://&amp;lt;domain&amp;nbsp;and path&amp;gt;/IFrameCommunicator.html'. Either the 'unsafe-inline' keyword, a hash ('sha256-rQFcSQ+uPvBBS36Ebz2AA8DWF5LxdwuQKeLhxEfN+Ec='), or a nonce ('nonce-...') is required to enable inline execution. The action has been blocked.&lt;/P&gt;&lt;P&gt;This is ONLY happening in the sandbox environments, not in production environments. However, our company replies on these sandbox environments to test and support hundreds of customers, but now we can no longer use them.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Dec 2025 17:35:39 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94677#M58559</guid>
      <dc:creator>aacampillo</dc:creator>
      <dc:date>2025-12-07T17:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94735#M58587</link>
      <description>&lt;P&gt;UPDATE:&amp;nbsp;I talked with Authorize.Net Support, and they have acknowledged the issue and told me they are working on a fix. However, they were unable to provide a timeline for resolution.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 16:06:41 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/94735#M58587</guid>
      <dc:creator>aacampillo</dc:creator>
      <dc:date>2025-12-19T16:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/95009#M58710</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/33346"&gt;@aacampillo&lt;/a&gt;&amp;nbsp;have you received any update on the upcoming fix? We continue to see the issue as of today.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 18:23:33 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/95009#M58710</guid>
      <dc:creator>NAntiman</dc:creator>
      <dc:date>2026-03-23T18:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/95011#M58712</link>
      <description>&lt;P&gt;&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/71584"&gt;@NAntiman&lt;/a&gt;&amp;nbsp;No update yet. I will reach out to them again now that it's been a few months.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 21:17:37 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/95011#M58712</guid>
      <dc:creator>aacampillo</dc:creator>
      <dc:date>2026-03-23T21:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Accept Hosted iFrame - Sandbox issue only - Browsers started enforcing a content security policy</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/96011#M59221</link>
      <description>&lt;P&gt;We’ve seen similar differences between sandbox and production with hosted payment integrations. The fact that the same iframe works in production but gets blocked in the sandbox makes it seem more like an environment-side CSP change than an integration issue. It would be helpful to know whether the sandbox policy has since been updated or if there’s a recommended workaround for testing&lt;A href="https://locksmithvineland.com/" target="_self"&gt;.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Sep 2026 19:10:08 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Accept-Hosted-iFrame-Sandbox-issue-only-Browsers-started/m-p/96011#M59221</guid>
      <dc:creator>edwardharry</dc:creator>
      <dc:date>2026-09-19T19:10:08Z</dc:date>
    </item>
  </channel>
</rss>

