Answered

Is there a way to serve messenger with Content Security Policy without style-src: 'unsafe-inline'

  • 22 June 2022
  • 1 reply
  • 53 views

We would need to add Content Security Policy to our application. I saw this article on Intercom Help. There it is stated to use 'unsafe-inline' but I am wondering is there a way not to use it, since we would like avoid that in our policy?

icon

Best answer by Evan P 27 June 2022, 13:11

View original

1 reply

Hey @stefan m​, 👋 thanks for reaching out! I'm one of the Support Engineers here @ Intercom! 👍

 

Currently 'unsafe-inline' is required for various aspects of Intercom to work properly. If you choose not to include one or some of the policies listed in that article you have looked at, then Intercom will potentially not function correctly.

 

You definitely aren't the first to reach out about our CSP so I will make sure to flag this with our Product team so they aware of it. I hope this clarifies.

Reply