---
title: "Important: #105856 - Allow site-specific Content-Security-Policy endpoints"
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:important-105856-1737555887"
source: "Changelog/12.4.x/Important-105856-AllowSite-specificContent-Security-PolicyEndpoints.rst"
typo3-version: "12.4.x"
typo3-major: 12
type: "important"
issue: 105856
forge: "https://forge.typo3.org/issues/105856"
tags: ["Backend", "Frontend", "YAML", "ext:backend"]
rendered: "2026-10-08T12:25:00+00:00"
---

# Important: #105856 - Allow site-specific Content-Security-Policy endpoints {#important-105856-1737555887}

See [forge#105856](https://forge.typo3.org/issues/105856)

## Description {#description}

The way Content-Security-Policy reporting endpoints are configured has
been enhanced. Administrators can now disable the reporting endpoint
globally or configure it per site as needed.

The global scope-specific setting `contentSecurityPolicyReportingUrl` can
be set to zero ('0') to disable the CSP reporting endpoint:

-   `[TYPO3_CONF_VARS][FE][contentSecurityPolicyReportingUrl] = '0'`
-   `[TYPO3_CONF_VARS][BE][contentSecurityPolicyReportingUrl] = '0'`

Additionally, the behavior of the reporting endpoint can also be
configured per site via `sites/<my-site>/csp.yaml`.

The new disposition-specific property `reportingUrl` can either be:

-   `reportingUrl (true)` to enable the reporting endpoint
-   `reportingUrl (false)` to disable the reporting endpoint
-   `reportingUrl (string)` to use the given value as external reporting endpoint

If defined, the site-specific configuration takes precedence over
the global configuration.

In case the explicitly disabled endpoint still would be called, the
server-side process responds with a 403 HTTP error message.

### Example: Disabling the reporting endpoint {#example-disabling-the-reporting-endpoint}

**config/sites/\<my-site>/csp.yaml**

```yaml
enforce:
  inheritDefault: true
  mutations: {}
  reportingUrl: false
```

### Example: Using custom external reporting endpoint {#example-using-custom-external-reporting-endpoint}

**config/sites/\<my-site>/csp.yaml**

```yaml
enforce:
  inheritDefault: true
  mutations: {}
  reportingUrl: https://example.org/csp-report
```
