<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting CSP errors even after allowlisting Hubspot Tracking Code on web product in APIs &amp; Integrations</title>
    <link>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/675617#M55522</link>
    <description>&lt;P&gt;&lt;SPAN&gt;The problem we are facing when adding HubSpot scripts and functionality to our web product is that they are loaded from various domains and sub-domains. I have a CSP in place for security reasons, so all scripts, iframe, form, image sources, etc., need to be put on the allowlist before they're loaded.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm sure there's a good reason why the scripts come from so many different domains, but e&lt;/SPAN&gt;&lt;SPAN&gt;very time we put one domain on the allowlist, it shows another domain on the network window while inspecting. Can I get a list of all possible domains/subdomains needed to allowlist to resolve the CSP error and track all the functionalities of the Hubspot script, or could someone tell me a workaround? As of right now, the process of allowlisting is full of friction.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2022 18:51:41 GMT</pubDate>
    <dc:creator>HBaranwal</dc:creator>
    <dc:date>2022-08-05T18:51:41Z</dc:date>
    <item>
      <title>Getting CSP errors even after allowlisting Hubspot Tracking Code on web product</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/675617#M55522</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The problem we are facing when adding HubSpot scripts and functionality to our web product is that they are loaded from various domains and sub-domains. I have a CSP in place for security reasons, so all scripts, iframe, form, image sources, etc., need to be put on the allowlist before they're loaded.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm sure there's a good reason why the scripts come from so many different domains, but e&lt;/SPAN&gt;&lt;SPAN&gt;very time we put one domain on the allowlist, it shows another domain on the network window while inspecting. Can I get a list of all possible domains/subdomains needed to allowlist to resolve the CSP error and track all the functionalities of the Hubspot script, or could someone tell me a workaround? As of right now, the process of allowlisting is full of friction.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 18:51:41 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/675617#M55522</guid>
      <dc:creator>HBaranwal</dc:creator>
      <dc:date>2022-08-05T18:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Getting CSP errors even after allowlisting Hubspot script on web product</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/676456#M55582</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/428917"&gt;@HBaranwal&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":waving_hand:"&gt;👋&lt;/span&gt; Welcome to the community. Hey,&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/20405"&gt;@himanshurauthan&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/193060"&gt;@JBeatty&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/166093"&gt;@miljkovicmisa&lt;/a&gt;&amp;nbsp;have you ever solved for this or a similar issue?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for taking a look! — Jaycee&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 17:02:38 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/676456#M55582</guid>
      <dc:creator>Jaycee_Lewis</dc:creator>
      <dc:date>2022-08-05T17:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Getting CSP errors even after allowlisting Hubspot script on web product</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/687443#M56489</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/127074"&gt;@Jaycee_Lewis&lt;/a&gt;,thank you for tagging me in! Sure I would love to give it a try.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So &lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/428917"&gt;@HBaranwal&lt;/a&gt;&amp;nbsp;I would suggest you try the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;script-src&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;https://*.hubspot.com&lt;/P&gt;
&lt;P&gt;&lt;A href="https://js.hscollectedforms.net/" target="_blank" rel="noopener" data-link-card="true"&gt;https://js.hscollectedforms.net&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://js.hsadspixel.net/" target="_blank" rel="noopener" data-link-card="true"&gt;https://js.hsadspixel.net&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;https://*.hs-scripts.com&lt;/P&gt;
&lt;P&gt;&lt;A href="https://js.hs-banner.com/" target="_blank" rel="noopener" data-link-card="true"&gt;https://js.hs-banner.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://js.hs-analytics.net/" target="_blank" rel="noopener" data-link-card="true"&gt;https://js.hs-analytics.net&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://forms.hsforms.com/" target="_blank" rel="noopener" data-link-card="true"&gt;https://forms.hsforms.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;https://*.usemessages.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;img-src&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;https://*.hsforms.com&lt;/P&gt;
&lt;P&gt;https://*.hubspot.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;connect-src&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;https://*.hubspot.com&lt;/P&gt;
&lt;P&gt;https://*.hubapi.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;frame-src&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;https://*.hubspot.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this will resolve your problem!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2022 10:23:19 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/687443#M56489</guid>
      <dc:creator>himanshurauthan</dc:creator>
      <dc:date>2022-08-31T10:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Getting CSP errors even after allowlisting Hubspot script on web product</title>
      <link>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/830471#M66221</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.hubspot.com/t5/user/viewprofilepage/user-id/20405"&gt;@himanshurauthan&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I hope you are doing well.&lt;/P&gt;&lt;P&gt;I am facing a similar issue myself with the CSP header. My question is: how can we update the CSP header in the Domain security settings? Whenever I add the code to the CSP, my site throws errors and breaks. I want to narrow down the CSP to avoid broad issues in my domain. To achieve this, I need to add 'object-src' and 'script-src' directives to 'self', limiting the handling of objects and scripts to only those on my own domain, or specifying trusted domains.&lt;/P&gt;&lt;P&gt;I've read and understood an &lt;A href="https://knowledge.hubspot.com/domains-and-urls/ssl-and-domain-security-in-hubspot" target="_blank" rel="noopener"&gt;article&lt;/A&gt; about setting up the CSP header, but it's too confusing for me to implement on my domain. Could you please guide me through this issue? Your help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 06:18:56 GMT</pubDate>
      <guid>https://community.hubspot.com/t5/APIs-Integrations/Getting-CSP-errors-even-after-allowlisting-Hubspot-Tracking-Code/m-p/830471#M66221</guid>
      <dc:creator>THC</dc:creator>
      <dc:date>2023-08-07T06:18:56Z</dc:date>
    </item>
  </channel>
</rss>

