SAP Knowledge Base Article - Public

3794319 - Live Direct Connection issue due to Content Security Policy in SAP Analytics Cloud (SAC) after QRC3 upgrade

Symptom

  • All Live Direct connections and also all stories based on such connection fail to work in SAP Analytics Cloud (SAC) after QRC3 upgrade
  • Error shown in UI: 
    • We couldn't connect to your <Live Data System>. For more information, see our troubleshooting page. 
  • Error observed in Chrome Console Log:
    • Live HANA: Connecting to 'https://<HANA Host:Port>/sap/bc/ina/service/v2/GetServerInfo' violates the following Content Security Policy directive: "connect-src 'self' data
    • Live BW: Connecting to 'https://<BW Host:Port>/sap/bw/ina/GetServerInfo?sap-client=003&saml2=disabled' violates the following Content Security Policy directive: "connect-src 'self' data
    • Live Datasphere: Connecting to 'https://<Datasphere tenant FQDN>/mobileapp/oauth2/api/v1/token' violates the following Content Security Policy directive: "connect-src 'self' data
  • Live Tunnel connections are not affected

Environment

  • SAP Analytics Cloud, Enterprise Edition
  • All Live Direct Connections

Reproducing the Issue

  1. Log on to SAC tenant.
  2. Try to create/edit a new Live Direct connection.
  3. Click OK button after entering connection info and credential.
    => Error "We couldn't connect to your <Live Data System>. For more information, see our troubleshooting page. " appears.
    => Check the browser console and observe a CSP connect-src violation.
    => This issue could be also observed when trying to create or open a story based on existing live direct connection.

Cause

  • Content Security Policy (CSP) has been enabled on your tenant under System > Administration > Security, which is a security mechanism that restricts the sources from which the browser is allowed to load resources (SAC Help).
  • The live system is not added as trusted CSP domain of connect-src directive, blocking the token endpoint call required for the live connection.

Resolution

  1. In SAP Analytics Cloud, go to System > Administration > Security.
  2. Choose Edit on the Security tab.
  3. Scroll to the Content Security Policy section.
    • Option 1: Disable Content Security Policy
    • Option 2 (Recommended): Add the URL of live system (i.e., https://example.com:443) as a Trusted CSP Domain under the connect-src directive.
  4. Save the changes.
  5. Refresh the browser page and then try to test the live direct connections and stories.

See Also


Your feedback is important to help us improve our knowledge base.

Keywords

SAP Analytics Cloud, SAC, Datasphere, live data connection, direct connection, HANA, Content Security Policy, CSP, connect-src, trusted domains, token endpoint, oauth2, browser console error, story fails to open, upgrade regression , KBA , LOD-ANA-LDC-HAN , SAC Live Data Connection HANA , LOD-ANA-LDC-WBI , SAC Live Data Connection WEBI , LOD-ANA-LDC-BW , SAC Live Data Connection BW , LOD-ANA-LDC-UNV , SAC Live Data Connection Universe , Problem

Product

SAP Analytics Cloud 1.0