# How to updates CSP policy via environment variables (Docker)

**URL:** <https://help.nextcloud.com/t/how-to-updates-csp-policy-via-environment-variables-docker/115795>\
**Category:** ℹ️ Support\
**Tags:** docker, csp\
**Created:** [May 8, 2021, 9:04am UTC](https://help.nextcloud.com/t/how-to-updates-csp-policy-via-environment-variables-docker/115795 "2021-05-08T09:04:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yaya911](https://help.nextcloud.com/letter_avatar/yaya911/32/5_5575768a8748004e209b776fc1b2916d.png) [@Yaya911](https://help.nextcloud.com/u/Yaya911)\
**Post date:** [May 8, 2021, 9:04am UTC](https://help.nextcloud.com/t/how-to-updates-csp-policy-via-environment-variables-docker/115795/1 "2021-05-08T09:04:03Z")

</div>

I need to update nextcloud’s CSP default settings to allow form-action submission from sub-domains such as [login.site.com](http://login.site.com), [app.site.com](http://app.site.com) and so on. Nextcloud is hosted as [cloud.site.com](http://cloud.site.com).

Using latest nextcloud from docker hub (nextcloud:fpm).  
Also using vouch to provide OAuth2.0 to protected App. Users are authenticated by nextcloud.

Chrome Error message:

```auto
Refused to send form data to 'https://login.XXXX.com.au/' 
because it violates the following Content Security Policy directive: 

https://cloud.XXXX.com.au/login/flow/grant?stateToken=XXX&clientIdentifier=XXX&oauthState=XXX

"form-action 'self' https://app.XXXX.com.au/".

```

Current nextclud form-action is restricted to self. I think that doesnt allow using nextcloud as SSO server unless hosted on the same host.

my vouch is on a sub-host and I think that is my problem.

Adding something like “\*.site.com” might solve my problem.

---

<div class="post-metadata">

**Author:** ![Yaya911](https://help.nextcloud.com/letter_avatar/yaya911/32/5_5575768a8748004e209b776fc1b2916d.png) [@Yaya911](https://help.nextcloud.com/u/Yaya911)\
**Post date:** [May 8, 2021, 4:07pm UTC](https://help.nextcloud.com/t/how-to-updates-csp-policy-via-environment-variables-docker/115795/2 "2021-05-08T16:07:59Z")

</div>

I should add, I have a semi-solution for this problem but its not ideal. That is to edit ContentSecurityPolicy.php and add the trusted domain, submitting form-action, to the array $allowedFormActionDomains.  
But that means everytime I remove the docker container - I have to re-edit it.

---

<div class="post-metadata">

**Author:** ![disgustipated](https://help.nextcloud.com/letter_avatar/disgustipated/32/5_5575768a8748004e209b776fc1b2916d.png) [@disgustipated](https://help.nextcloud.com/u/disgustipated)\
**Post date:** [December 6, 2024, 7:48pm UTC](https://help.nextcloud.com/t/how-to-updates-csp-policy-via-environment-variables-docker/115795/3 "2024-12-06T19:48:26Z")

</div>

Thanks for the pointer to the php file, it worked perfectly editing that. did you ever find a way to have this set in docker vars? I have my html folder mounted on a volume outside of the container but i think it will still get overwritten when its updated, will have to see on the next update.

To expand on how to manually allow this after updating:  
Locate the ContentSecurityPolicy.php located in your container volume, for example mine is

```auto
/nextcloud/html/lib/public/AppFramework/Http/ContentSecurityPolicy.php

```

From there edit this

```auto
	/** @var array Domains which can embed this Nextcloud instance */
	protected $allowedFrameAncestors = [
		'\'self\' https://*.yourdomain.url https://yourdomain.url',
	];

```

replace yourdomain.url with the page you are allowing to embed

edit:  
for those that find this method in the future. using the hide toolbars app is a much easier way of doing this. on top of allowing the headers to be hidden it exposes a way of allowing CSP urls directly in the config.php  
see more details here

> [@Hide header when embeding appointment in iframe](https://help.nextcloud.com/t/hide-header-when-embeding-appointment-in-iframe/212142):
>
> I’m successfully displaying the appointment scheduling page in an iframe on a separate website. I’m trying to hide the header that displays in the iframe but cant figure out what needs to be added. when im using dev tools i can delete this node and the header will be gone. [image] this is the code im using to embed the iframe \<iframe src="https://MYAPPOINTMENTURL" onload='javascript:(function(o){o.style.height=o.contentWindow.document.body.scrollHeight+"px";}(this));' style="height:800px;widt…

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [May 22, 2025, 5:49am UTC](https://help.nextcloud.com/t/how-to-updates-csp-policy-via-environment-variables-docker/115795/4 "2025-05-22T05:49:19Z")

</div>


