User Guide Cancel

Content security policy

  1. Adobe Fonts User Guide
  2. Introduction
    1. System and subscription requirements
    2. Browser and OS support
    3. Add fonts on your computer
    4. Add fonts to your website
    5. Add fonts on CC Mobile
  3. Font licensing
    1. Fonts added from Adobe Fonts
    2. Web fonts from Adobe Fonts
    3. Creative Cloud for enterprise customers
    4. Removed fonts
    5. Why aren't these fonts included in my Creative Cloud subscription?
    6. Why am I being asked to purchase a license for fonts in Adobe Fonts?
    7. Adobe Fonts not available to Adobe IDs registered in China
  4. Getting and using fonts
    1. Using Adobe Fonts in Creative Cloud apps
    2. Manage your fonts
    3. Find fonts from images
    4. Resolve missing fonts in desktop applications
    5. Using fonts in InDesign
    6. Fonts and typography
    7. Using web fonts in HTML5 Canvas documents
    8. Using fonts in InCopy
    9. Using web fonts in Muse
    10. Packaging font files
    11. Troubleshooting guide: Adding fonts
    12. Added fonts aren't showing to the font menu
    13. "Unable to add one or more fonts" or "A font with the same name is already installed"
    14. What happens when a font I'm using is updated by the foundry?
    15. Hide fonts in Adobe programs
  5. Web design and development
    1. Add fonts to your website
    2. Troubleshooting guide: Adding fonts to a website
    3. Troubleshoot font issues
    4. Using web fonts in HTML email or newsletters
    5. Using web fonts with Accelerated Mobile Pages (AMP)
    6. CSS selectors
    7. Customize web font performance with font-display settings
    8. Embed codes
    9. Dynamic subsetting & web font serving
    10. Font events
    11. Why are my web fonts from use.typekit.net?
    12. Site can't connect to use.typekit.net
    13. Using web fonts with CodePen
    14. Browser and OS support
    15. Domains
    16. Using web fonts when developing locally
    17. Content security policy
    18. Printing web fonts
  6. Language support and OpenType features
    1. Language support and subsetting
    2. Using OpenType features
    3. Syntax for OpenType features in CSS
  7. Font technology
    1. OpenType-SVG color fonts
    2. Ten Mincho: important points on updating from Version 1.000

The Content Security Policy (CSP) is a means for restricting which scripts and resources are allowed on your website. You could, for example, use CSP to stop external scripts from being executed on your website.

CSPs are not recommended for use with Adobe Fonts

While it is possible to use a CSP with web fonts from Adobe on the same page, we do not recommend it.  The CSP policy does not allow you to set an exception for inline styles added by a script from a specific domain. If you specify an unsafe-inline exception for styles, it will apply to all styles from all domains.

Adobe Fonts uses inline styles and fonts as data URIs to provide our service, and making exceptions for these negates a lot of the protection provided by a CSP. 

Using a CSP

If you do wish to use a CSP, follow these instructions to properly set your security directives. Take care, as failure to properly follow all of these instructions could result in an inadvertent violation of the Terms of Use for the web font service.

  1. The first directive is to allow scripts to load from our CDN, use.typekit.net:

    script-src 'self' use.typekit.net;
  2. Next, you need to allow stylesheets from use.typekit.net and specify unsafe-inline to allow scripts from all domains (including use.typekit.net) to use inline styles. This is required for font events to work.

    style-src 'self' 'unsafe-inline' use.typekit.net;
  3. The final requirement is an exception for images from p.typekit.net. Font loading uses a tracking image from this domain to calculate font usage and pay foundries appropriately for the use of their fonts.

    img-src 'self' p.typekit.net;
  4. Optionally, you can add an exception for our performance metrics. Performance metrics are sent at random intervals and are used to monitor the performance of our font network.

    connect-src performance.typekit.net

You should combine these directives into a single policy and set the Content-Security-Policy header on all your HTTP(S) responses. To support older versions of Chrome, Firefox, and Safari, you’ll also need to include the X-Content-Security-Policy and X-WebKit-CSP headers. For more information, please refer to the W3C CSP specification.

Adobe, Inc.

Dapatkan bantuan lebih cepat dan lebih mudah

Pengguna baru?