Script loading - Fluid Topics - Latest

Fluid Topics Configuration and Administration Guide

Category
Reference Guides
Audience
public
Version
Latest

To prevent remote code execution attacks, the Script loading toggle improves portal security by adding strict-dynamic to the Content Security Policy (CSP) of the portal.

This means that Fluid Topics uses a cryptographic nonce to validate the execution of inline JavaScript.

  • This toggle is active by default for tenants created after the release of this feature.
  • Enabling this feature does not have any impact on Custom JavaScript code or Custom components.