# Is unsafe-eval required for script-src in the content-security-policy for Kibana 6.7.1?

**URL:** <https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298>\
**Category:** Kibana\
**Created:** [April 3, 2020, 12:36am UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298 "2020-04-03T00:36:58Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![cjin62](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjin62/32/66480_2.png) [@cjin62](https://discuss.elastic.co/u/cjin62)\
**Post date:** [April 3, 2020, 5:05am UTC](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298/3 "2020-04-03T05:05:56Z")

</div>

Hi @LizaD - Thank you for the quick reply. I already reviewed that post before I raised my question - it unfortunately does not address my question.

What I'd like to do is to set the `csp.rules` parameter in the kibana.yml file to no longer have unsafe-eval for script-src - to make it more secure:

[https://www.elastic.co/guide/en/kibana/6.7/settings.html](https://www.elastic.co/guide/en/kibana/6.7/settings.html)

However, I do not know whether removing unsafe-eval from script-src will cause any issues with the list of Kibana functions below:

- Discover
- Visualize
- Dashboard
- Timelion
- Alerting
- Dev Tools
- Management
- Security

---

_[View the full topic](https://discuss.elastic.co/t/is-unsafe-eval-required-for-script-src-in-the-content-security-policy-for-kibana-6-7-1/226298)._
