Skip to content

Content Security Policy

Content Security Policy is an important part of building production-ready Module Federation systems. This lesson explains what content security policy means, how it works, and how to apply it with practical examples you can reuse.

Content Security Policy Overview

Content Security Policy is a building block you will reach for often in Module Federation. It keeps related logic together and makes your intent obvious to reviewers and future maintainers.

When you learn content security policy properly, you avoid the guesswork that leads to bugs and rework. The example below shows the shape you will use in most real Module Federation projects.

const ProductList = React.lazy(() =>
  import('catalog/ProductList').catch(() => ({
    default: () => <p>Catalog is temporarily unavailable</p>,
  })),
);

Always provide a fallback so a failing remote degrades gracefully instead of crashing the shell.

Content Security Policy Example

new ModuleFederationPlugin({
  name: 'app',
  filename: 'remoteEntry.js',
  exposes: { './Widget': './src/Widget' },
  remotes: { other: 'other@http://host/remoteEntry.js' },
  shared: { react: { singleton: true } },
});
  • Start from a minimal Content Security Policy example and grow it only as needed.
  • Keep configuration explicit so Content Security Policy behaves the same in every environment.
  • Name things clearly so teammates understand your Content Security Policy at a glance.
  • Add tests around Content Security Policy early to lock in expected behaviour.

Module Federation Cheatsheet

Key Module Federation settings related to content security policy.

Option Example Purpose
name name: 'shell' Unique container name
filename filename: 'remoteEntry.js' Remote entry manifest
exposes exposes: { './X': './src/X' } Modules a remote shares
remotes remotes: { app: 'app@url' } Remotes a host consumes
shared shared: { react: { singleton: true } } Deduplicate libraries
lazy load import('remote/Module') Load remotes on demand
Suspense <Suspense fallback={...}> Handle async loading

How Content Security Policy Works in Module Federation

Content Security Policy builds on Module Federation's ability to load code from another independently built and deployed application at runtime. Each app can be a host, a remote, or both.

Always provide a fallback so a failing remote degrades gracefully instead of crashing the shell.

  • Remotes expose modules through a remoteEntry.js manifest.
  • Hosts declare remotes and import exposed modules dynamically.
  • Shared dependencies are deduplicated, ideally as singletons.
  • Each micro frontend builds and deploys on its own schedule.

Practical Guidance for Content Security Policy

In production, content security policy needs careful version management and graceful failure handling. Align shared dependency versions and always render a fallback when a remote cannot load.

Concern Recommendation
Shared versions Use singletons with requiredVersion
Runtime errors Wrap remotes in error boundaries and fallbacks
Deployment Resolve remotes from a runtime manifest
Performance Lazy-load remotes and cache remoteEntry.js

Common Mistakes

  • Copying content security policy snippets without understanding what each line does.
  • Skipping error handling and edge cases when wiring up content security policy.
  • Leaving content security policy untested, so regressions slip into production.
  • Over-engineering content security policy before you actually need the extra flexibility.

Key Takeaways

  • Content Security Policy is a core part of working effectively with Module Federation.
  • Start small and keep content security policy focused on a single responsibility.
  • Apply consistent patterns so content security policy scales across your project.
  • Test and document content security policy to keep it maintainable over time.

Pro Tip

Pair content security policy with automated tests from day one. It is far cheaper to catch Module Federation regressions in CI than in production.