No Code Attached Yet
avatar mariantanase
mariantanase
3 Jul 2025

Steps to reproduce the issue

I activate the plugin 'System - HTTP Header'.
Activated options on CSP tab.
Adding some directives:

  • Policy Directive default-src, Value 'self', Client Both
  • Policy Directive script-src, Value 'self', Client Site
  • Policy Directive style-src, Value 'self' 'unsafe-inline', Client Site
  • Policy Directive img-src, Value 'self' data:, Client Site

Now after scanning with securityheaders.com, I receve this warning:
Content-Security-Policy No valid directives found in policy.

Expected result

The CSP directives are interpreted

Actual result

On Header response there's no values:
content-security-policy:
content-security-policy-report-only:

System information (as much as possible)

Joomla 5.3.1
PHP 8.3.22

Additional comments

avatar mariantanase mariantanase - open - 3 Jul 2025
avatar joomla-cms-bot joomla-cms-bot - change - 3 Jul 2025
Labels Added: No Code Attached Yet
avatar joomla-cms-bot joomla-cms-bot - labeled - 3 Jul 2025
avatar brianteeman
brianteeman - comment - 3 Jul 2025
avatar mariantanase
mariantanase - comment - 3 Jul 2025

I configured the correct plugin parameters, but the CSP values are blank

Image
Image

avatar brianteeman
brianteeman - comment - 3 Jul 2025

sorry don't know what to say to help you as it works for me with the settings i have shown

avatar mariantanase
mariantanase - comment - 3 Jul 2025

Maybe it could be an option in Akeeba Admin tools that conflicts, but I haven't found it.

avatar brianteeman
brianteeman - comment - 3 Jul 2025

Not that I can see as I have admintools on that site and i dont see any option in there that would conflict

avatar mariantanase
mariantanase - comment - 3 Jul 2025

Ok, I found the guilty. The plugin 'System - GDPR' cause the problem.

avatar mariantanase mariantanase - change - 3 Jul 2025
Status New Closed
Closed_Date 0000-00-00 00:00:00 2025-07-03 12:30:24
Closed_By mariantanase
avatar mariantanase mariantanase - close - 3 Jul 2025

Add a Comment

Login with GitHub to post a comment