如何在web.config中配置CSP以允许SharePoint中DirectLine Bot运行?
Problem Analysis
Your error happens because the Content Security Policy (CSP) in your web.config doesn't explicitly allow WebSocket (wss://) connections to the Direct Line service. When the connect-src directive isn't defined in your CSP, browsers fall back to using the default-src rules. Even though default-src includes https:, some browsers don't automatically map wss:// (WebSocket Secure) to https: for connection sources—which is why your bot's stream URL gets blocked.
Solution: Update Your CSP to Allow Direct Line Resources
You need to add a connect-src directive to your CSP that explicitly permits connections to directline.botframework.com via both https:// (for API calls) and wss:// (for real-time chat streams). Here's how to modify your web.config entry:
Original CSP:
<add name="Content-Security-Policy" value="default-src https: data: 'unsafe-inline' 'unsafe-eval'" />
Updated CSP with explicit connect-src:
<add name="Content-Security-Policy" value="default-src https: data: 'unsafe-inline' 'unsafe-eval'; connect-src https://directline.botframework.com wss://directline.botframework.com;" />
Why This Works
connect-srcspecifies which URLs the browser can connect to via fetch, WebSocket, XMLHttpRequest, and similar mechanisms.- Explicitly listing
https://directline.botframework.comallows REST API calls to the Direct Line service. - Adding
wss://directline.botframework.comunlocks the real-time WebSocket stream needed for the bot to send and receive messages instantly.
Additional Checks (If Issues Persist)
If you still run into CSP errors after this change, double-check if your Web Chat script is loaded from a CDN (like https://cdn.botframework.com). If so, add that domain to the script-src directive to allow loading the Web Chat library:
<add name="Content-Security-Policy" value="default-src https: data: 'unsafe-inline' 'unsafe-eval'; connect-src https://directline.botframework.com wss://directline.botframework.com; script-src https://cdn.botframework.com;" />
After updating the web.config, restart your SharePoint site to apply the changes, then test the bot—your WebSocket connection should now be allowed without disabling the entire CSP.
内容的提问来源于stack exchange,提问作者Jegan Baskaran

