Symptom
- Content Security Policy is blocking multiple third-party scripts the career site uses to function.
- Review browser developer console logs for error messages related to blocked scripts, the error message says: "Refused to connect to 'https://stats.g.doubleclick.net/j/collect?t=ab&cde=1&_f=3&g=1&_h=i92&klm=NO-12345678-1&pqr=12345678.1234567890&stu=123456789&wxyz=1234567890&_abc=123456789.1234567890&_d=ABCDEFGhIJKLMN~&o=1234567890' because it violates the following Content Security Policy directive..."
Environment
SAP SuccessFactors Recruiting Marketing
Reproducing the Issue
- Go to Career Site
- Observe that third-party scripts are being blocked due to Content Security Policy settings
- Review browser developer console logs for error messages related to blocked scripts
Cause
The required domains for third-party scripts were not manually added to the Content Security Policy allowlist in Career Site Builder (CSB).
Resolution
- Manually add all required domains to the allowlist in Career Site Builder (CSB) -> Settings -> Data Privacy & Security Settings -> Data Protection.
- Verify that the blocked scripts are now allowed and the career site functions correctly.
See Also
- 3476408 - Use of Default-src and Object-src directive in Content Security Policy of RMK Career site - Recruiting Marketing
- 3044364 - Enabling Content Security Policy for RMK Site - Recruiting Marketing
- 3062705 - Image doesn't load in the career site after enabling Content Security Policy- Recruiting Marketing
- Finding and Manually Adding Domains to the Content Security Policy Allowlist - Guide
Keywords
RMK, content security policy, CSP, blocked scripts, function, third-party scripts, career site, Career Site Builder, CSB, allowlist, default-src, directive, blocked URLs, Data Privacy & Security Settings, Data Protection , KBA , LOD-SF-RMK-CSB , Career Site Builder , Problem
Product
SAP SuccessFactors Recruiting all versions
SAP Knowledge Base Article - Public