Skip to content

Content Security Policy

In this lesson you will learn content security policy in single-spa, why it matters within security, and how to use it correctly with clear, copy-ready examples.

Content Security Policy Overview

Content Security Policy is a building block you will reach for often in single-spa. It keeps related logic together and makes your intent obvious to reviewers and future maintainers.

When you learn content security policy properly, you avoid the guesswork that leads to bugs and rework. The example below shows the shape you will use in most real single-spa projects.

import { registerApplication, start } from 'single-spa';

registerApplication({
  name: '@org/app',
  app: () => System.import('@org/app'),
  activeWhen: ['/app'],
});

start();

single-spa orchestrates multiple framework apps on one page through a root config.

Content Security Policy Example

registerApplication({
  name: '@org/app',
  app: () => System.import('@org/app'),
  activeWhen: ['/app'],
});
start();
  • Start from a minimal Content Security Policy example and grow it only as needed.
  • Keep configuration explicit so Content Security Policy behaves the same in every environment.
  • Name things clearly so teammates understand your Content Security Policy at a glance.
  • Add tests around Content Security Policy early to lock in expected behaviour.

Single-SPA Cheatsheet

Core single-spa APIs related to content security policy.

API Example Purpose
registerApplication registerApplication({ name, app, activeWhen }) Register a micro frontend
activeWhen activeWhen: ['/checkout'] Route ownership
start start() Begin routing
bootstrap export async function bootstrap() One-time setup
mount export async function mount(props) Render the app
unmount export async function unmount(props) Clean up the app
import map systemjs-importmap Locate app bundles

How Content Security Policy Works in Single-SPA

Content Security Policy is part of how single-spa lets multiple applications — even in different frameworks — coexist on one page. A root config registers each app and controls when it is active.

single-spa orchestrates multiple framework apps on one page through a root config.

  • A root config registers apps and calls start().
  • Each app exports bootstrap, mount, and unmount lifecycles.
  • activeWhen decides which routes each app owns.
  • Import maps resolve each app's bundle at runtime.

Practical Guidance for Content Security Policy

For reliable micro frontends, content security policy should isolate failures and keep shared state minimal. Let each team own its app end to end while agreeing on a few shared contracts.

Concern Recommendation
Isolation One app's crash should not break others
Shared state Prefer shared utility modules over globals
Routing Keep activeWhen rules explicit and non-overlapping
Deployment Release via import-map updates per app

Common Mistakes

  • Copying content security policy snippets without understanding what each line does.
  • Skipping error handling and edge cases when wiring up content security policy.
  • Leaving content security policy untested, so regressions slip into production.
  • Over-engineering content security policy before you actually need the extra flexibility.

Key Takeaways

  • Content Security Policy is a core part of working effectively with single-spa.
  • Start small and keep content security policy focused on a single responsibility.
  • Apply consistent patterns so content security policy scales across your project.
  • Test and document content security policy to keep it maintainable over time.

Pro Tip

Pair content security policy with automated tests from day one. It is far cheaper to catch single-spa regressions in CI than in production.