Jazz Forum Welcome to the Jazz Community Forum Connect and collaborate with IBM Engineering experts and users

How to allow CLM integration with OSLC Consumer to work with Content-Security-Policy

 Unicom Focal Point integration with CLM is broken with latest 6.0.5 due to Content-Security-Policy, getting Refused to display '<URL for the iFrame>' in a frame because an ancestor violates the following Content Security Policy directive: "frame-ancestors 'self' <URL for host2>".


Is there any setting in CLM 6.0.5  to allow FP domain URL to work with  Content-Security-Policy.

0 votes



2 answers

Permanent link

Two things you can try:

1. In Firefox, open about:config and set security.csp.enable = false.  In Chrome, disable the Content Security Policy (various Chrome plug-ins available).

2. Set the following Advanced Properties:

Jazz Web UI (Ajax Services) >> Prevent clickjacking (X-Frame-Options) >> true
Jazz Web UI (Ajax Services) >> Clickjacking whitelist >> <all servers - e.g. Unicom Focal Point, CLM, etc.>

0 votes


Permanent link

 @paul 
it's not working in CLM 

0 votes

Comments

 Please open a Case (https://www.ibm.com/mysupport) for IBM Support to investigate this symptom in your environment.

Your answer

Register or log in to post your answer.

Dashboards and work items are no longer publicly available, so some links may be invalid. We now provide similar information through other means. Learn more here.

Search context
Follow this question

By Email: 

Once you sign in you will be able to subscribe for any updates here.

By RSS:

Answers
Answers and Comments
Question details
× 10,936
× 7,494

Question asked: Feb 27 '18, 12:23 p.m.

Question was seen: 5,192 times

Last updated: Jul 29 '19, 3:27 p.m.

Confirmation Cancel Confirm