SAP Knowledge Base Article - Public

3670910 - Permissions-Policy Header

Symptom

Is it possible to enable a Permissions-Policy Header in SuccessFactors. 

Environment

SAP SuccessFactors HCM 

Resolution

The Architecture and Security teams have reviewed SAP's position on Permissions-Policy header.

Security headers are only a second line of defence and an optional security setting. They are not a security vulnerability on their own. 
Permissions-Policy header is currently not a security standard for SAP.

The Security and Architecture teams state that there is no security risk or gap in this area.
Therefore, we will not be enhancing SuccessFactors to support the configuration and management of Permissions-Policy header.

To verify the feasibility of having this included in a future version of the system, please submit this enhancement request to our Influence Page by following the instructions available in the article 2090228.

See Also

Keywords

SuccessFactors, Permissions-Policy header, Security.  , KBA , LOD-SF-PLT-PSI , Product Security Inquiries , Product Enhancement

Product

SAP SuccessFactors HCM Core all versions