Your Community is getting an upgrade!
Read about our partnership with Higher Logic and how we will build the next generation of the Instructure Community.
Found this content helpful? Log in or sign up to leave a like!
Hi,
This is a question for Canvas admins, particularly those in higher ed. Is anyone using the Content Security Policy? What issues have you encountered if so? If not, why not? We have started using it and I have run into a few pain points, one severe enough that it is now listed in Known Issues and they are working on a fix. I am interested in hearing from other who are using the CSP or have used it.
Thank you,
Sylvia Sotomayor
Canvas Admin, Distance Education
Cerro Coso Community College
Does canvas sell or share my information ?
We haven't enabled it so far -- Content Security Policy is a good example of a feature that needs a user story in its documentation that explains the set of problems the feature solves*, summarizes the arguments for enabling it and spells out the foreseeable ramifications of enabling it (e.g. arbitrary iFramed content in Pages breaking, which I'm guessing is a possibility if it's enabled).
* for example, I'm still unclear if the main use case is disabling malicious JS from sketchy sites embedded in iframes, or it's for adding support for the recent more restrictive browser content policies, or both
Agreed re the use cases. We implemented it because it seemed a good idea to add security and then disabled it when it became unworkable.
To interact with Panda Bot, our automated chatbot, you need to sign up or log in:
Sign InTo interact with Panda Bot, our automated chatbot, you need to sign up or log in:
Sign In