CMS MADE SIMPLE FORGE

CMS Made Simple Core

 

[#12854] Not a bug report , just a report of use case with $config['admin_csp_header'] = 'self' with update basic policies to work

avatar
Created By: Philippe Thomas (filto)
Date Submitted: Sun Sep 13 21:19:25 -0400 2026

Assigned To: Fernando Morgado (JoMorg)
Version: 2.2.24
CMSMS Version: 2.2.24
Severity: None
Resolution: Works For Me
State: Open
Summary:
Not a bug report , just a report of use case with $config['admin_csp_header'] = 'self' with update basic policies to work
Detailed Description:
in lib/include.php Ligne 135

------------------
if($config['admin_csp_header'] === 'self')
{
     $policies = [
           "default-src 'self'",
            "script-src 'unsafe-inline' 'self'",
            "style-src 'unsafe-inline' 'self'",
    ];

------------------
# detailed report of tests on my side

For Content-Security-Policy :

admin module Design manager 1.2.0 jquery-1.11.1.min.js:2
need : script-src 'unsafe-eval'

admin modules Content manager 1.1.15 and News 2.51.14  and certainly others
need : img-src data:

admin module manager 2.2.0
need : img-src https://cdn.cmsmadesimple.org

all admin function preview
need : frame-src 'self'

admin module user guide 1.1
need : frame-src https://player.vimeo.com

admin module AceSyntax 1.0.1 used in USER DEFINED TAG
need : worker-src blob:

then i tested in lib/include.php Ligne 135 like this

-------
if($config['admin_csp_header'] === 'self')
{
     $policies = [
           "default-src 'self'",
           "script-src 'unsafe-inline' 'unsafe-eval' 'self'",

            "style-src 'unsafe-inline' 'self'",

            "img-src 'self' data: https://cdn.cmsmadesimple.org",

            "frame-src 'self' https://player.vimeo.com",

           "worker-src blob:",

    ];

-----------------------

Others tested CSP settings :

Cross-Origin-Embedder-Policy: 

# recommended
header("Cross-Origin-Embedder-Policy: require-corp");

#but at this time admin module manage need this (cf below my remark)
header("Cross-Origin-Embedder-Policy: credentialless");

#same way admin module admin module user guide 1.1 (it is unsafe)
header("Cross-Origin-Embedder-Policy: unsafe-none");

------
X-Frame-Options

/*admin module Search 1.55 */
header("X-Frame-Options: SAMEORIGIN");
-----
Ressources from your sites :
https://cdn.cmsmadesimple.org/modules/  *module_name*  ./icon.png

Cross-Origin-Resource-Policy is not defined on ressources like :

https://cdn.cmsmadesimple.org/modules/MAS_Paypal/icon.png
https://cdn.cmsmadesimple.org/modules/MAS_AuthHub/icon.png
etc...

these urls need to have Cross-Origin-Resource-Policy: cross-origin


I don't read yet your module creation guide
but if it's not, it may be good to speek about csp requirement
especially for external resources...

otherwise, it will be a nightmare to manage for those who are not familiar with
CSP management

i have tested a very secure version front and back hand with hash and nonce
easy to setup
but it take time to test it to validte

hope my little report help

just  ONE little bug in admin/systeminfo.php with PHP 8.4 and 8.5
 Constant E_STRICT is deprecated since 8.4
everything else works perfectly

Thanks for your work
this cms is always the best for me


History

Comments
avatar
Date: 2026-09-21 00:40
Posted By: Philippe Thomas (filto)

In fact, it’s easier to manage directly with htaccess files 
one in root dir
and one admin dir

actually with cms_admin_sendheaders function
you have to manage CORP and not CSP for files like:
admin/style.php
admin/cms_js_setup.php


      
Updates

Updated: 2026-09-14 11:21
description: in lib/include.php Ligne 135 ------------------ if($config['admin_csp_header'] === 'self') { $policies = [ "default-src 'self'", "script-src 'unsafe-inline' 'self'", "style-src 'unsafe-inline' 'self'", => in lib/include.php Ligne 135 ------------------ if($config['admin_csp_header'] === 'self') { $policies = [ "default-src 'self'", "script-src 'unsafe-inline' 'self'", "style-src 'unsafe-inline' 'self'",

Updated: 2026-09-13 21:31
resolution_id: => 11