You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在web.config中配置CSP以允许SharePoint中DirectLine Bot运行?

Fixing Content Security Policy for DirectLine Bot in SharePoint

Problem Analysis

Your error happens because the Content Security Policy (CSP) in your web.config doesn't explicitly allow WebSocket (wss://) connections to the Direct Line service. When the connect-src directive isn't defined in your CSP, browsers fall back to using the default-src rules. Even though default-src includes https:, some browsers don't automatically map wss:// (WebSocket Secure) to https: for connection sources—which is why your bot's stream URL gets blocked.

Solution: Update Your CSP to Allow Direct Line Resources

You need to add a connect-src directive to your CSP that explicitly permits connections to directline.botframework.com via both https:// (for API calls) and wss:// (for real-time chat streams). Here's how to modify your web.config entry:

Original CSP:

<add name="Content-Security-Policy" value="default-src https: data: 'unsafe-inline' 'unsafe-eval'" />

Updated CSP with explicit connect-src:

<add name="Content-Security-Policy" value="default-src https: data: 'unsafe-inline' 'unsafe-eval'; connect-src https://directline.botframework.com wss://directline.botframework.com;" />

Why This Works

  • connect-src specifies which URLs the browser can connect to via fetch, WebSocket, XMLHttpRequest, and similar mechanisms.
  • Explicitly listing https://directline.botframework.com allows REST API calls to the Direct Line service.
  • Adding wss://directline.botframework.com unlocks the real-time WebSocket stream needed for the bot to send and receive messages instantly.

Additional Checks (If Issues Persist)

If you still run into CSP errors after this change, double-check if your Web Chat script is loaded from a CDN (like https://cdn.botframework.com). If so, add that domain to the script-src directive to allow loading the Web Chat library:

<add name="Content-Security-Policy" value="default-src https: data: 'unsafe-inline' 'unsafe-eval'; connect-src https://directline.botframework.com wss://directline.botframework.com; script-src https://cdn.botframework.com;" />

After updating the web.config, restart your SharePoint site to apply the changes, then test the bot—your WebSocket connection should now be allowed without disabling the entire CSP.


内容的提问来源于stack exchange,提问作者Jegan Baskaran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 09:09:17