Articles with the tag:
Close
Changelog
Close
Try in the cloud
Help Center
ONLYOFFICE Docs Developer Edition

Working with plugins when using CSP

ONLYOFFICE Docsv6.4 ONLYOFFICE Docs changelog

Version 6.4.1

Release date: 09/28/2021

Version 6.4.0

Release date: 08/26/2021

Version 6.3.2

Release date: 08/10/2021

Version 6.3.1

Release date: 06/08/2021

Version 6.3.0

Release date: 05/20/2021

Version 6.2.2

Release date: 04/19/2021

Version 6.2.1

Release date: 03/31/2021

Version 6.2.0

Release date: 03/01/2021

Version 6.1.1

Release date: 01/28/2021

Version 6.1.0

Release date: 12/02/2020

Version 6.0.2

Release date: 11/12/2020

Version 6.0.1

Release date: 10/28/2020

Version 6.0.0

Release date: 10/14/2020

Version 5.6.5

Release date: 09/21/2020

Version 5.6.4

Release date: 09/08/2020

Version 5.6.3

Release date: 08/17/2020

Version 5.6.2

Release date: 08/07/2020

Version 5.6.1

Release date: 08/05/2020

Version 5.6.0

Release date: 07/29/2020

Version 5.5.3

Release date: 05/22/2020

Version 5.5.1

Release date: 04/09/2020

Version 5.5.0

Release date: 03/05/2020

Version 5.4.2

Release date: 11/27/2019

Version 5.4.1

Release date: 10/02/2019

Version 5.4.0

Release date: 09/03/2019

Version 5.3.4

Release date: 07/16/2019

Version 5.3.2

Release date: 06/24/2019

Version 5.3.1

Release date: 06/06/2019

Version 5.3.0

Release date: 05/28/2019

Version 5.2.8

Release date: 02/05/2019

Version 5.2.7

Release date: 01/16/2019

Version 5.2.6

Release date: 12/25/2018

Version 5.2.4

Release date: 12/12/2018

Version 5.2.3

Release date: 10/31/2018

Version 5.2.2

Release date: 10/05/2018

Version 5.2.0

Release date: 09/28/2018

Version 5.1.5

Release date: 07/18/2018

Version 5.1.4

Release date: 05/24/2018

Version 5.1.3

Release date: 04/27/2018

Version 5.1.2

Release date: 04/11/2018

Version 5.1.1

Release date: 04/05/2018

Version 5.1.0

Release date: 03/28/2018

Version 5.0.7

Release date: 01/16/2018

Version 5.0.6

Release date: 12/11/2017

Version 5.0.5

Release date: 11/28/2017

Version 5.0.4

Release date: 11/14/2017

Version 5.0.3

Release date: 11/02/2017

Version 5.0.2 SaaS only

Release date: 10/13/2017

Version 5.0.1 SaaS only

Release date: 10/05/2017

Version 5.0.0 SaaS only

Release date: 09/23/2017

Version 4.4.4

Release date: 09/13/2017

Windows-only release

See changelog on GitHub

Version 4.4.3

Release date: 08/14/2017

Version 4.4.2

Release date: 07/24/2017

Version 4.4.1

Release date: 07/05/2017

Version 4.3.6

Release date: 06/14/2017

Version 4.3.5

Release date: 06/05/2017

Version 4.3.4

Release date: 05/16/2017

Version 4.3.3

Release date: 04/28/2017

Version 4.3.2

Release date: 04/17/2017

Version 4.3.1

Release date: 04/06/2017

Version 4.3.0

Release date: 04/03/2017

Version 4.2.11

Release date: 03/13/2017

Version 4.2.10

Release date: 02/20/2017

Version 4.2.9

Release date: 02/14/2017

Version 4.2.8

Release date: 02/06/2017

Version 4.2.7

Release date: 02/01/2017

Version 4.2.5

Release date: 01/16/2017

Version 4.2.4

Release date: 01/09/2017

Version 4.2.3

Release date: 12/23/2016

Version 4.2.2

Release date: 12/21/2016

Version 4.2.1

Release date: 12/06/2016

Version 4.2.0

Release date: 12/01/2016

Version 4.1.8

Release date: 11/03/2016

Version 4.1.7

Release date: 11/01/2016

Version 4.1.6

Release date: 10/26/2016

Version 4.1.5

Release date: 10/13/2016

Version 4.1.4

Release date: 10/07/2016

Version 4.1.3

Release date: 09/28/2016

Version 4.1.2

Release date: 09/22/2016

Version 4.0.3

Release date: 08/04/2016

Version 4.0.2

Release date: 08/03/2016

Introduction

Content Security Policy (CSP) is a security standard intended to prevent some threats, such as Cross-Site Scripting (XSS) attacks etc. When CSP is enabled, it allows to load the contents from the approved sources only. Particularly, it prohibits requests to third-party domains which have not been explicitly allowed.

If you are using ONLYOFFICE Docs (Enterprise Edition or Developer Edition) integrated with your web solution, and if CSP is enabled on your web server to improve safety and security measures, the CSP default settings may cause some issues. ONLYOFFICE Online Editors include a number of plugins, some of which use third-party resources and make requests to third-party domains, e.g. the YouTube plugin. As CSP prohibits requests to third-party domains, this prevents plugins from proper working, e.g. block loading YouTube video.

Adding third-party domains to the list of allowed sources

For plugins to work correctly you need to allow requests to certain domains (the full list of domains is available below). This can be done by changing the HTTP header which enables CSP. Depending on the solution that you use, this header can be located in different files. This instruction describes the basic principles, not the individual cases. The header should look like this:

Header set Content-Security-Policy "default-src 'self'; script-src 'self'; connect-src 'self';  img-src 'self'; style-src 'self';"

This string contains directives which specify the allowed sources for different types of content: scripts, stylesheets, fonts, images, HTML5 <audio> or <video> elements etc.

The default-src directive is applied when a directive for a certain resource type is not specified.

‘self’ means that the contents can be loaded from the the current domain only.

It’s necessary to edit the default-src directive adding the trusted domains values:

default-src 'self' *.trusted1.com *.trusted2.com

This will allow to make requests to and load contents from the specified trusted domains *.trusted1.com and *.trusted2.com including their subdomains.

Third-party domain list

The following plugins make requests to third-party domains:

Plugin Domain
clipart https://openclipart.org
speech https://code.responsivevoice.org
youtube https://www.youtube.com
synonim https://words.bighugelabs.com
translate https://translate.yandex.net
ocr https://cdn.rawgit.com

The following plugins from the listed above are included into ONLYOFFICE Online Editors by default: ocr, speech, synonim, translate, youtube.

The clipart plugin is not included into online editors, but it is available on https://github.com/ONLYOFFICE/sdkjs-plugins and you can add it to editors manually.

To add all the mentioned domains into the list of allowed sources, the HTTP header should look like this:

Header set Content-Security-Policy "default-src 'self' *openclipart.org *code.responsivevoice.org *www.youtube.com *words.bighugelabs.com *translate.yandex.net *cdn.rawgit.com; script-src 'self'; connect-src 'self'; img-src 'self'; style-src 'self';"
if you additionally configured ONLYOFFICE Enterprise Edition to use CSP and enabled the wordpress and easybib plugins, you’ll also need to specify the *wordpress.com and *easybib.com domains.
Download Host on your own server Available for
Docker, Windows and Linux
You Might Also Like This:
Close