# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Canvas LMS REST Content Security Policy Settings API version: 1.0.0 extends: openapi/canvas-content-security-policy-settings-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 8 - target: $.paths['/v1/courses/{course_id}/csp_settings'].get update: x-apievangelist-phrasing: intent: Get a course's content security policy settings effect: read questions: - Is the content security policy enabled for my course? - Does a course inherit its CSP setting from its parent account? instructions: - text: Get the CSP settings for course {course_id}. slots: course_id: path.course_id - text: Show whether content security policy is on for course {course_id}. slots: course_id: path.course_id method: generated generated: '2026-10-01' - target: $.paths['/v1/courses/{course_id}/csp_settings'].put update: x-apievangelist-phrasing: intent: Turn a course's CSP on, off or back to inherited effect: write questions: - How do I turn off the content security policy for one course? - Can a course go back to using its account's CSP setting? instructions: - text: Set the CSP status of course {course_id} to {status}. slots: course_id: path.course_id status: requestBody.status - text: Make course {course_id} inherit the content security policy from its account. slots: course_id: path.course_id method: generated generated: '2026-10-01' - target: $.paths['/v1/accounts/{account_id}/csp_settings'].get update: x-apievangelist-phrasing: intent: Get an account's content security policy settings effect: read questions: - What CSP settings and allowed domains does my account have? - Are an account's content security policy settings locked for sub-accounts? instructions: - text: Get the CSP settings for account {account_id}. slots: account_id: path.account_id - text: Show account {account_id}'s content security policy and its allowed domains. slots: account_id: path.account_id method: generated generated: '2026-10-01' - target: $.paths['/v1/accounts/{account_id}/csp_settings'].put update: x-apievangelist-phrasing: intent: Turn an account's CSP on, off or back to inherited effect: write questions: - How do I enable the content security policy for an account and its sub-accounts? - Can a sub-account clear its explicit CSP setting and inherit from the parent? instructions: - text: Set the CSP status of account {account_id} to {status}. slots: account_id: path.account_id status: requestBody.status - text: Explicitly enable content security policy on account {account_id}. slots: account_id: path.account_id method: generated generated: '2026-10-01' - target: $.paths['/v1/accounts/{account_id}/csp_settings/lock'].put update: x-apievangelist-phrasing: intent: Lock CSP settings for sub-accounts and courses effect: write questions: - Can I stop sub-accounts and courses from changing the CSP setting I chose? - Why can't I lock CSP settings when my account inherits them? instructions: - text: Set CSP settings lock on account {account_id} to {settings_locked}. slots: account_id: path.account_id settings_locked: requestBody.settings_locked - text: Lock account {account_id}'s content security policy so sub-accounts and courses cannot override it. slots: account_id: path.account_id method: generated generated: '2026-10-01' - target: $.paths['/v1/accounts/{account_id}/csp_settings/domains'].post update: x-apievangelist-phrasing: intent: Allow a domain in an account's CSP effect: write questions: - How do I whitelist a domain so it can load under the account content security policy? - Will an allowed domain take effect if CSP isn't explicitly enabled? instructions: - text: Add {domain} to the allowed CSP domains for account {account_id}. slots: domain: requestBody.domain account_id: path.account_id - text: Allow content from {domain} in account {account_id}. slots: domain: requestBody.domain account_id: path.account_id method: generated generated: '2026-10-01' - target: $.paths['/v1/accounts/{account_id}/csp_settings/domains'].delete update: x-apievangelist-phrasing: intent: Remove an allowed domain from an account's CSP effect: destructive questions: - How do I take a domain off my account's CSP allow list? - Can I revoke a previously allowed CSP domain? instructions: - text: Remove {domain} from the allowed CSP domains of account {account_id}. slots: domain: query.domain account_id: path.account_id - text: Stop allowing {domain} under account {account_id}'s content security policy. slots: domain: query.domain account_id: path.account_id method: generated generated: '2026-10-01' - target: $.paths['/v1/accounts/{account_id}/csp_settings/domains/batch_create'].post update: x-apievangelist-phrasing: intent: Allow several domains in an account's CSP at once effect: write questions: - Can I add a whole list of domains to the CSP allow list in one request? - Is there a batch way to whitelist several domains for an account? instructions: - text: Add domains {domains} to account {account_id}'s CSP allow list in one batch. slots: domains: requestBody.domains account_id: path.account_id - text: 'Batch allow these domains for account {account_id}: {domains}.' slots: account_id: path.account_id domains: requestBody.domains method: generated generated: '2026-10-01'