---
title: "Important: #106715 - Apply CSP sandbox mode to fileadmin's .htaccess configuration"
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:important-106715-1747646438"
source: "Changelog/12.4.x/Important-106715-ApplyCSPSandboxModeToFileadminsHtaccessConfiguration.rst"
typo3-version: "12.4.x"
typo3-major: 12
type: "important"
issue: 106715
forge: "https://forge.typo3.org/issues/106715"
tags: ["ext:install"]
rendered: "2026-10-08T12:25:00+00:00"
---

# Important: #106715 - Apply CSP sandbox mode to fileadmin's .htaccess configuration {#important-106715-1747646438}

See [forge#106715](https://forge.typo3.org/issues/106715)

## Description {#description}

The directive `Content-Security-Policy: sandbox;` restricts
several client-side actions for files that may contain markup
(e.g., HTML, SVG):

-   Disallows downloads
-   Disallows form submissions
-   Disallows modals and popups
-   Disallows orientation and pointer lock
-   Disallows presentation sessions
-   Disallows navigation of the top-level browsing context

This applies only to resources located in the default file storage
location (e.g., `/fileadmin/`). Rendering Fluid templates from a
different location within the CMS application uses TYPO3’s dynamic
CSP feature instead.

Since the file `/fileadmin/.htaccess` is not automatically updated
once it has been created in a TYPO3 installation, maintainers must manually
adjust the web server configuration.

Below are the required changes to introduce the `sandbox` directive:

```diff
 <IfModule mod_headers.c>
     # matching requested *.pdf files only (strict rules block Safari showing PDF documents)
     <FilesMatch "\.pdf$">
         Header set Content-Security-Policy "default-src 'self' 'unsafe-inline'; script-src 'none'; object-src 'self'; plugin-types application/pdf;"
     </FilesMatch>
     # matching requested *.svg files only (allows using inline styles when serving SVG files)
     <FilesMatch "\.svg">
-        Header set Content-Security-Policy "default-src 'self'; script-src 'none'; style-src 'unsafe-inline'; object-src 'none';"
+        Header set Content-Security-Policy "default-src 'self'; script-src 'none'; style-src 'unsafe-inline'; object-src 'none'; sandbox;"
     </FilesMatch>
     # matching anything else, using negative lookbehind pattern
     <FilesMatch "(?<!\.(?:pdf|svg))$">
-        Header set Content-Security-Policy "default-src 'self'; script-src 'none'; style-src 'none'; object-src 'none';"
+        Header set Content-Security-Policy "default-src 'self'; script-src 'none'; style-src 'none'; object-src 'none'; sandbox;"
     </FilesMatch>
```
