Setting Up Content Security Policy for Map Services
Content Security Policy (CSP) helps protect the application by controlling the external resources that a browser can load. To use map services that access external URLs, you must add the origins for those URLs to the applicable Oracle Permitting and Licensing profile options.
Adding the origins allows CSP to connect to the external map service and load images from it. If the required origins aren't allowlisted, GIS map functionality might not load.
For map services, add the applicable origins to both the
ORA_OPAL_ALLOWED_CONNECT_SRC and
ORA_OPAL_ALLOWED_IMG_SRC profile options.
To add map service origins to the profile options:
-
Access the Functional Setup Manager by selecting Setup and Maintenance in the user's Settings and Actions menu.
-
Click the Tasks panel tab:

-
Select the Search link in the menu.
-
On the Search page, enter "Manage Administrator Profile Values" and click the search icon.
-
Click the Manage Administrator Profile Values task link.
-
In the Search: Profile Option section on the Manage Administrator Profile Values page, enter this in the Profile Option Code field:
ORA_OPAL_ALLOWED_CONNECT_SRC -
Click Search.
-
Select the
ORA_OPAL_ALLOWED_CONNECT_SRCprofile option in the results. -
In the Profile Values section, enter the origins for the external URLs used by your map services:
-
If a row with a Profile Level of Site exists, enter the origins in the Profile Value field.
-
If a row with a Profile Level of Site doesn't exist, add a row, select Site as the profile level, and enter the origins in the Profile Value field.
If you have more than one origin, enter the values as a space-separated list.
-
-
Click Save.
-
Search for and select the
ORA_OPAL_ALLOWED_IMG_SRCprofile option. -
At the Site profile level, enter the applicable map service origins as a space-separated list.
-
Click Save.
Content Security Policy Profile Options
The following profile options specify the domains that can be allowlisted for
different types of external resources. In addition to map service origins, you can
add other applicable external URLs to the
ORA_OPAL_ALLOWED_CONNECT_SRC and
ORA_OPAL_ALLOWED_IMG_SRC profile options as needed.
|
Profile Option Code |
Description |
|---|---|
ORA_OPAL_ALLOWED_CONNECT_SRC |
Specifies a space-separated list of domains that are valid sources for AJAX, XHR, and fetch requests. |
ORA_OPAL_ALLOWED_FONT_SRC |
Specifies a space-separated list of domains that are valid sources for fonts. |
ORA_OPAL_ALLOWED_FRAME_SRC |
Specifies a space-separated list of domains that are valid sources for iframes. |
ORA_OPAL_ALLOWED_IMG_SRC |
Specifies a space-separated list of domains that are valid sources for images and favicons. |
ORA_OPAL_ALLOWED_MEDIA_SRC |
Specifies a space-separated list of domains that are valid sources for media loaded using audio and video elements. |
ORA_OPAL_ALLOWED_SCRIPT_SRC |
Specifies a space-separated list of domains that are valid sources for JavaScript. |
ORA_OPAL_ALLOWED_STYLE_SRC |
Specifies a space-separated list of domains that are valid sources for style sheets. |
ORA_OPAL_ALLOWED_WORKER_SRC |
Specifies a space-separated list of domains that are valid sources for Worker, SharedWorker, or ServiceWorker scripts. |