Symptom
Content Security Policy (CSP) headers are enabled in SAP SuccessFactors. However, in the console logs, CSP headers appear for certain pages but are missing on others.
Environment
SAP SuccessFactors HCM Suite
Cause
The absence of CSP headers on certain pages is due to the high level of customization allowed for the content on these pages. The static CSP policy implemented in the product may not support these customizable functions.
Resolution
This behavior is expected in 2511 version due to the static CSP policy implemented in the product.
A new feature will be introduced in 1H2026 for 2605 version (April 13th for Preview / May 16th for Production) to enable administrators to view and manage CSP exceptions directly from the Application Security Settings.
Refer to SAP SuccessFactors Release Information for updated information regarding features releases.
See Also
Help Portal - Content Security Policy
Keywords
Content Security Policy, CSP, Headers, SFASE-3069, INC19726578 , KBA , LOD-SF-PLT-PSI , Product Security Inquiries , Product Enhancement
SAP Knowledge Base Article - Public