# Discourse Advertising Plugin (Ads)

**URL:** https://meta.discourse.org/t/discourse-advertising-plugin-ads/33734
**Category:** Plugin
**Tags:** official, advertising, included-in-core
**Created:** [September 25, 2015, 5:21am UTC](https://meta.discourse.org/t/discourse-advertising-plugin-ads/33734 "2015-09-25T05:21:36Z")
**Posts on this page:** 1
**Showing post:** 372

<div class="post-metadata">

### Author: ![MarkDoerr](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/markdoerr/32/549630_2.png) [@MarkDoerr](https://meta.discourse.org/u/MarkDoerr)
#### Post date: [November 1, 2024, 12:29am UTC](https://meta.discourse.org/t/discourse-advertising-plugin-ads/33734/372 "2024-11-01T00:29:27Z")

</div>

Thanks for the reminder that I needed to update the OP. Done. 🙂

> [@omarfilip](#):
>
> The [content security policy guidance](https://meta.discourse.org/t/discourse-advertising-plugin-ads/33734#fixing-content-security-policy-issues-19) is outdated. What’s the latest?

We implemented a [`strict-dynamic` CSP](https://meta.discourse.org/t/content-security-policy-now-uses-strict-dynamic/298172) a while back and you shouldn’t need to do any further setup.

We’d recommend removing `https:` or `unsafe-inline` unless you need them for some specific reason, as they do not provide any protection against XSS vulnerabilities.

---

_[View the full topic](https://meta.discourse.org/t/discourse-advertising-plugin-ads/33734)._
