Answered

Is there a way to serve Intercom with Content Security Policy without style-src: 'unsafe-inline'

  • 22 June 2022
  • 6 replies
  • 292 views

We would need to add Content Security Policy to our application. I saw this article on Intercom Help. There it is stated to use 'unsafe-inline' but I am wondering is there a way not to use it, since we would like avoid that in our policy?

icon

Best answer by Evan P 27 June 2022, 14:47

View original

6 replies

Hey again @stefan m​ . 👋

 

 

I replied to your other post with an answer here but just incase that didn't show I'll copy my message here.

 

 

"Currently 'unsafe-inline' is required for various aspects of Intercom to work properly. If you choose not to include one or some of the policies listed in that article you have looked at, then Intercom will potentially not function correctly.

 

You definitely aren't the first to reach out about our CSP so I will make sure to flag this with our Product team so they aware of it. I hope this clarifies."

@evan p​ 

Thanks for your reply 👍

@Evan P Hello Evan,

Any progress on using Intercom with CSP?

 

Pascal

Userlevel 2
Badge +3

Hi @Pascal Bourque , It’s Mat from the Support Engineering Team 😀

We are constantly working to enhance the intercom. 

You can find more about using CSP in Intercom in this article.

Please let me know if that was the answer you were looking for 😎

Hey Mat

 

Thanks for the update! There still seems to be a requirement to include

style-src:
  'unsafe-inline’

 

Is there any way to avoid this, or any updates underway? 

This is quite crucial for us & cybersecurity in general.

Userlevel 4
Badge +5

Hey there @Dries Hendrickx !

That ‘unsafe-inline’ has been flagged with our team, but as of right now it is still a requirement.

Reply