Open navigation

Security, CSP, and consent

Allow only the Flatzer host required by the widget, adapt the directive to your policy, and load the agent after consent when needed.

Conservative starting point
Content-Security-Policy:
  script-src 'self' https://flatzer.com;
  connect-src 'self' https://flatzer.com;
  img-src 'self' data: https://flatzer.com;
  frame-src https://flatzer.com;

Start with the minimum host

The loader and its transport use https://flatzer.com. Start by allowing that origin in script-src and connect-src; add img-src or frame-src only if the browser reports that configured content needs them. Adapt existing nonces and directives instead of replacing your whole policy.