# Why Cookie Consent Doesn't Show Up?

**URL:** https://meta.discourse.org/t/why-cookie-consent-doesnt-show-up/108175
**Category:** Support
**Created:** [2월 2, 2019, 1:06오전 UTC](https://meta.discourse.org/t/why-cookie-consent-doesnt-show-up/108175 "2019-02-02T01:06:52Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![tshenry](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tshenry/32/119495_2.png) [@tshenry](https://meta.discourse.org/u/tshenry)
#### Post date: [2월 2, 2019, 1:21오전 UTC](https://meta.discourse.org/t/why-cookie-consent-doesnt-show-up/108175/2 "2019-02-02T01:21:00Z")

</div>

This is due to Content Security Policy. You will need to whitelist the script source per these instructions (particularly note [this part](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243#heading--extend-default-csp)):

> [@Mitigate XSS Attacks with Content Security Policy](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243):
>
> bookmark This guide explains how to use Content Security Policy (CSP) to mitigate Cross-Site Scripting (XSS) attacks in Discourse. It covers CSP basics, configuration, and best practices. person_raising_hand Required user level: Administrator Summary Content Security Policy (CSP) is a crucial security feature in Discourse that helps protect against Cross-Site Scripting (XSS) and other injection attacks. This guide covers the basics of CSP, how it’s implemented in Discourse, and how to c…

---

_[View the full topic](https://meta.discourse.org/t/why-cookie-consent-doesnt-show-up/108175)._
