SAP Knowledge Base Article - Preview

3705943 - The request has been blocked due to a violation of the Content Security Policy (CSP) directive

Symptom

  • The application operation got failed with blank page
  • The following info can be seen from HTTPWatch trace:
    Framing 'blob:https://<host>/<URL>' violates the following Content Security Policy directive: "default-src 'self'". The request has been blocked. Note that 'frame-src' was not explicitly set, so 'default-src' is used as a fallback.
  • The issue only occurs when accessing the application through SAP Web Dispatcher, no issue when accessing backend system directly


Read more...

Environment

SAP Web Dispatcher

Product

SAP Web Dispatcher all versions

Keywords

CSP header Blocked blank  , KBA , BC-CST-WDP , Web Dispatcher , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.