ohmyhost.yaml; the deployment stores the policy with its artifact. A declaration enables that interface, but does not prove an external SDK, OAuth flow or exported application works. Test the actual browser flow after deployment.
connect also accepts WSS. No wildcard, URL path or inline/eval exception is accepted. Omitted groups retain restrictive defaults. Browser declarations do not authorize server fetch: that uses the separate runtime.egress.allow with at most thirteen exact HTTPS origins.
Nonces and cookies
Next.js and TanStack Start HTML receive a freshx-nonce; the platform sets it on every rendered script/style tag, including hand-written blocks, and supplies a csp-nonce meta tag. Inline style attributes and event handlers remain blocked. Tags later created by browser code need that nonce. Vite, with or without a companion, and static pages permit no inline script/style code. Prefer ordinary CSS and scripts, and never nonce untrusted user markup.
The gateway replaces application CSP. It drops Set-Cookie with a Domain attribute, so use host-only, Secure, HttpOnly session cookies. Same-origin non-GET/HEAD requests carrying cookies must have the correct Origin. For a declared external origin, the application must also return that exact Access-Control-Allow-Origin, allowed methods/headers and, when selected, its own Access-Control-Allow-Credentials: true; a wildcard does not suffice. Undeclared CORS headers are removed. Keep the application’s own authentication and authorization checks.
A provider callback using a cross-origin form POST needs the matching declared origin/CORS policy. Register the actual Dev/Prod callback URLs and verify session creation, reload and logout. Do not infer compatibility from a redirect or a successful root page. External browser integrations, including a deliberately retained Supabase client, require their exact declared origins and their own application evidence; moving that service into managed Postgres is a separate decision.
Media and microphone
Video/audio playback and microphone access require exactly thispublic/_headers opt-in on a server HTML runtime: