Skip to content

SAML SSO Module - CORS Issue #5189

@avenjamin

Description

@avenjamin

Just bought the SAML SSO module and when pressing logout I'm seeing this error in the browser console:

Refused to load https://login.microsoftonline.com/....../saml2 because it does not appear in the form-action directive of the Content Security Policy.

Can the Logout URL be added to the header CSP which is currently this:

<meta http-equiv="Content-Security-Policy" content="default-src 'self' ; img-src * 'self' data:; font-src * 'self' data:; style-src * 'self' 'unsafe-inline'; form-action 'self'; frame-src * 'self'; script-src 'self' 'nonce-hkz3L3FGXs4c9isEFS7AICaAj'  ;">

FreeScout version: 1.8.203

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions