Content Security Policy (CSP)

Example Using Google Maps with a Content-Security-Policy

How to create a content security policy (CSP) that works with Google Maps.

You're going to need to specify at least two CSP directives to get CSP working with Google Maps, the script-src and the img-src directive.

The script-src directive

In order for the Google Maps JavaScript to load we need to allow the domain in our policy:

Your policy might look like this:


Without such a policy, we would get an error in our browser, for example:

Content Security Policy: The page's settings blocked the loading of a resource at ("script-src")

The img-src directive

You will notice that the images loaded may differ depening on what type of google map you are using. You may see something like this in your network log:

img-src data: * *.ggpht

Without this we might get an error in the console such as:

Refused to load the img '' because it violates the following Content Security Policy directive: "img-src 'self'".

A Minimal Google Maps CSP

A minimal Content-Security-Policy header that works with Google Maps might look like this:

Content-Security-Policy: script-src;img-src data: * *.ggpht

That is the minimum to get CSP working with Google Maps. You will probably need to add in additional directives to all for the rest of your app to work.

CSP Developer Field Guide

CSP Developer Field Guide

Want to learn more about CSP on the double? Grab a copy of the CSP Developer Field Guide. It's a short and sweet guide to help developers get up to speed quickly.

Grab a Copy