Content Security Policy (CSP) is a standard that prevents code injection attacks, such as cross-site scripting. A website declares approved origins of content that a browser can load to display website content. The upgrade process checks for custom user interface components in the registered Operational Reference Store (ORS) databases. If any components are found, the appropriate content security policy is applied to ensure that no custom interface components are blocked.
If custom user interface components are found, the content security policy is set to the defaults required for Multidomain MDM to function. The upgrade process then adds the following rules:
After you upgrade, customize the content security policy to secure your system and prevent code injection attacks. For more information about configuring the content security policy, see the