# Content-Security-Policy and other security HTTP headers

**URL:** <https://discourse.libretime.org/t/content-security-policy-and-other-security-http-headers/937>\
**Category:** Dev Talk\
**Created:** [June 11, 2021, 6:51am UTC](https://discourse.libretime.org/t/content-security-policy-and-other-security-http-headers/937 "2021-06-11T06:51:12Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![narcisgarcia](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.libretime.org/narcisgarcia/32/497_2.png) [@narcisgarcia](https://discourse.libretime.org/u/narcisgarcia)\
**Post date:** [June 11, 2021, 6:51am UTC](https://discourse.libretime.org/t/content-security-policy-and-other-security-http-headers/937/1 "2021-06-11T06:51:12Z")

</div>

Dashboard and other sections don’t show content unless I disable CSP & SOP.  
Issue open at:

> <https://github.com/LibreTime/libretime/issues/1106>
>
> I've just installed and started with LibreTime (I don't know how to see version …at web interface) and my website has following HTTP headers set:
> 
> \`\`\`
> Header set Strict-Transport-Security "max-age=15768000"
> Header set X-Content-Type-Options "nosniff"
> Header set X-Frame-Options "SAMEORIGIN"
> Header set X-XSS-Protection "1; mode=block"
> Header set Content-Security-Policy "default-src 'none'; img-src 'self' data:; media-src 'self'; script-src 'self'; style-src 'self' data:; font-src 'self' data:; object-src 'self'; base-uri 'self'; connect-src 'self'; form-action 'self'; frame-ancestors 'self'"
> Header set Referrer-Policy "same-origin"
> Header set Permissions-Policy "payment=()"
> \`\`\`
> Dashboard and other sections don't show content unless I disable completely the CSP line.
> 
> 1. LibreTime HTML/CSS/JS code should be cleaned to allow a strict website security and approve test in observatory.mozilla.org
> 2. In the meanwhile, what are the minimum requirements in CSP to LibreTime web interface fully works?
