# OIDC login not working because of content security headers

**URL:** <https://forums.percona.com/t/oidc-login-not-working-because-of-content-security-headers/38145>\
**Category:** Percona Everest\
**Created:** [May 29, 2025, 2:56pm UTC](https://forums.percona.com/t/oidc-login-not-working-because-of-content-security-headers/38145 "2025-05-29T14:56:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![silent](https://avatars.discourse-cdn.com/v4/letter/s/f08c70/32.png) [@silent](https://forums.percona.com/u/silent)\
**Post date:** [May 29, 2025, 2:56pm UTC](https://forums.percona.com/t/oidc-login-not-working-because-of-content-security-headers/38145/1 "2025-05-29T14:56:04Z")

</div>

Hello,

I just installed percona everest (HELM) with OIDC (using Authentik):

server:  
oidc:  
issuerUrl: “[https://auth.my.domain.io/application/o/everest/](https://auth.my.domain.io/application/o/everest/)”  
clientId: “xxx”  
scopes:  
- openid  
- profile  
- email  
- groups

Except because of the content security policy, my browser refuses to connect:

index-D5s3V9rx.js:373 Refused to connect to ‘[https://auth.my.domain/application/o/everest/.well-known/openid-configuration](https://auth.my.domain/application/o/everest/.well-known/openid-configuration)’ because it violates the following Content Security Policy directive: “connect-src ‘self’”.

Cde @ index-D5s3V9rx.js:37Understand this error  
index-D5s3V9rx.js:373 Fetch API cannot load [https://auth.my.domain/application/o/everest/.well-known/openid-configuration](https://auth.my.domain/application/o/everest/.well-known/openid-configuration). Refused to connect because it violates the document’s Content Security Policy.

So OIDC login does not work because of this, I can’t seem to find any setting that would help alleviate this situation.

---

<div class="post-metadata">

**Author:** ![an-toine](https://avatars.discourse-cdn.com/v4/letter/a/51bf81/32.png) [@an-toine](https://forums.percona.com/u/an-toine)\
**Post date:** [June 3, 2025, 9:38am UTC](https://forums.percona.com/t/oidc-login-not-working-because-of-content-security-headers/38145/2 "2025-06-03T09:38:54Z")

</div>

Hello,

I’m facing a similar issue with OIDC login using Keycloak as the backend.

Usually, the first login succeeds, but after a few hours, the WebUI returns a blank page with no option to connect.  
The only way to restore the login screen is to wipe browser cache and data for everest domain :

 ![csp error obfuscated](https://us1.discourse-cdn.com/flex019/uploads/percona1/original/3X/1/b/1b21b9f6468e4de62a58bd7ebe875176851b7e07.png)  
 ![login screen](https://us1.discourse-cdn.com/flex019/uploads/percona1/original/3X/c/5/c5c319b3968b60f5d9b4599ce3e97cc5487eca0d.png)

For clarity, here is the error reported by the browser (Firefox 128.11.0esr) console :

```auto
Content-Security-Policy : Les paramètres de la page ont empêché le chargement d’une ressource (frame-src) à l’adresse https://XXXXXXXX/realms/XXXXXXXXX/protocol/openid-connect/auth?client_id=XXXXXXXX&redirect_uri=XXXXXXXXX&response_type=code&scope=openid+profile+email+groups&state=XXXXX&code_challenge=XXXXXXXXX&code_challenge_method=S256&response_mode=query&prompt=none car elle enfreint la directive suivante : « default-src 'self' » 

Uncaught (in promise) ErrorTimeout: IFrame timed out without a response

```

To be clear, the first login is working, but subsequent ones are not.

Antoine
