API & site security

Manage the origins that may call WebSpace APIs and WebSocket from external browser apps, along with the CSP for deployed web pages.

External API origins and CSP settings

Allowed origins

Enter one origin per line.

https://app.example.com
https://*.example.com

A wildcard allows subdomains only. Registering https://*.example.com does not include https://example.com, so add it separately when needed. HTTPS is recommended for production services.

Origin permission defines the scope of cross-origin browser calls. Sign-in requirements and each SFN endpoint's ACL still apply.

Content-Security-Policy

  • Web app compatibility mode: Use when you need broad support for external CDNs and common web app behavior.
  • Strict mode: Restricts pages primarily to their own resources. Check compatibility first for existing pages that require inline scripts or eval.

Advanced settings let you add sources separately for scripts, styles, images, fonts, connections, media, frames, and frame ancestors. Add only required domains. After saving, verify sign-in, APIs, WebSocket, images, and iframes at the deployed address.

The policy is written to frontend/security.json. An incorrect CSP can block a valid page, so record the current values before changing them.