Built something you're proud of? Tell the story. A quick G2 review of App Engine or Build Agent helps other developers see what's possible on ServiceNow. Share your experience.

Content Securirty Policy Response Header for Scripted REST API

madalavenkat
Tera Contributor

Hello Team,

 

We have been trying to add a Content-Security-Policy (CSP) response header in our Scripted REST API by using the response.setHeader() method. However, the configured value is not being reflected in the browser — it always shows only frame-ancestors 'self'.

Is there any known limitation in ServiceNow for setting this response header?

For reference, our instance version is Xanadu.
We would appreciate your assistance in understanding this behavior and helping us resolve it.

0 REPLIES 0