#31639 – I need CSP security on one of my websites

Posted in ‘Akeeba Admin Tools for Joomla!’
This is a public ticket. Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.
Thursday, 08 August 2019 16:50 CDT
Hi, for one of my websites the client want the maximum level of security.

So I want to implement the missing CSP rules. I tested a lot of possibility's via the recommended site https://www.cspisawesome.com/
but all rules gave me the 500 error.

Is there some way to test what options there are that should be set? Some step by step hand-out?

Best regards, Hein
Custom Fields
Joomla! version (in x.y.z format) 3.9.10
PHP version (in x.y.z format) 7.2.21
Admin Tools version (x.y.z format) 5.3.3
 Best regards, Hein
Friday, 09 August 2019 03:22 CDT

what's listed in the site you linked refers to the headers to be used, the actual string that needs to be put inside the .htaccess file are different.
Please take a look at this site: https://content-security-policy.com/

The actual rule you have to create is something like this: Header set Content-Security-Policy "default-src 'self';"
Once you're happy with the result, please remember to set your custom rule inside the fiels Custom rules at the bottom of the .htacces file, so you won't lose them if you regenerate the file using the Htaccess Maker.

Davide Tampellini

Developer and Support Staff

Italian: native

English: good

Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Sunday, 08 September 2019 17:17 CDT
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.
This ticket is closed, therefore read-only. You can no longer reply to it. If you need to provide more information, please open a new ticket and mention this ticket's number.

Support Information

Working hours: Typically we work Monday to Friday, 9am to 7pm Cyprus timezone (EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets, but we cannot respond to them, outside of our working hours.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!

Cookies Notification - Action required

This website uses cookies to provide user authentication and improve your user experience. Please indicate whether you consent to our site placing these cookies on your device. You can change your preference later, from the controls which will be made available to you at the bottom of every page of our site.