Skip to main content

Custom scripts and allowed domains for your online booking and forms sites

The PracSuite online booking site and Online Forms site have a strict CSP (Content Security Policy) to protect practice security and patient privacy. By default, this blocks inline scripts such as Custom HTML tags in Google Tag Manager (GTM), and tags that load from or send data to outside domains that are not already allowed. Google Analytics, Google Tag Manager, Google Ads and HubSpot tracking is already allowed on both sites, and Meta Pixel is already allowed on the online booking site, so none of these need any changes.

Official advice from Google regarding using a CSP with Tag Manager can be found here, however you can find some basic steps on navigating this with the PracSuite booking site below.

Seeing a console error? Jump to Which setting fixes which problem.

To trigger Custom HTML using Google Tag Manager, turn on Allow Custom Scripts in Settings > Online Booking > Overview. Look for the Security & Tracking Protections section, turn on Allow Custom Scripts and save. If you use Online Forms, repeat this on the Online Forms settings page.

These settings change the security of your booking and forms sites. We recommend only changing them under the direction of your website developer, digital marketing agency or online ads specialist.

After this is turned on, any Custom HTML tags triggered in Google Tag Manager must also be modified to include a nonce parameter. The nonce is a one-time security code that PracSuite generates each time the page loads. Scripts without it are blocked. Steps 1 to 3 below show how to add it as a variable in GTM.

How to add the nonce in Google Tag Manager (steps 1 to 3)


1. Create a variable to store the nonce value

After turning on Allow Custom Scripts for the booking site, the first step is to create a User-Defined Variable in the relevant GTM account.

In the GTM account, select Variables on the left-hand side, and create a new variable.

Select the Edit pencil to configure the new variable.

Select DOM element.

Enter ps-staticjs as the Element ID and data-nonce as the Attribute Name.

Select Save to finalise these changes.

2. Confirm that the variable is working

If you're familiar with adding nonce parameters, skip to step 3.

After creating the variable, it's best to confirm that the nonce value is being written to the data-nonce variable correctly.

To do this, we will create a new Tag that will be triggered on loading the booking site.

Select Tags on the left-hand side and select New.

In the Tag Configuration section, select Custom HTML.

Paste in the code snippet below, which will allow you to confirm that the nonce value is being correctly stored in the data-nonce variable created in step 1 by writing it to the browser console.

<script nonce="{{data-nonce}}">
console.log("CSP-allowed script with nonce:", "{{data-nonce}}");
</script>

Also, enable the Support document.write option at the bottom of the Tag Configuration window.

Save this Tag and Publish these changes live.

If the steps above have been configured correctly, when loading the booking site, you should see the following text outputted to the browser console (displayed when pressing F12 on the keyboard).

With the variable confirmed as working, it's best that you pause or remove the example Tag created during this step so that it no longer outputs the variable to the browser console.

3. Apply the nonce parameter to your existing Custom HTML Tags.

If the variable created in step 1 is working correctly, the final step is to add the nonce="{{data-nonce}}" parameter to your existing Custom HTML Tags.

An example is shown below. Be sure to enable the Support document.write option at the bottom of the Tag Configuration window.

Once the relevant Tags have been modified to include the nonce parameter, Save and Publish these changes in GTM.


Tags that need access to another domain

The nonce only covers scripts that run inline code. If a tag also loads a file from, or sends data to, another company's website, or shows content from it in a frame, that domain must be added to Additional Allowed Domains. Adding a domain does not replace the nonce, and adding the nonce does not allow a domain. Many tags need both.

  1. Go to Settings > Online Booking > Overview (or the Online Forms settings page) and select Edit.

  2. Turn on Allow Custom Scripts. Allowed domains only apply while this is on. Then select Add under Additional Allowed Domains.

  3. Enter the domain your marketing provider has given you, for example track.yourmarketer.com.au. Enter just the domain name. If you paste a full web address, PracSuite removes the https:// and anything after the domain.

  4. Select Save.

Each domain is matched exactly. Adding yourmarketer.com.au does not also allow track.yourmarketer.com.au. To allow every subdomain, enter *.yourmarketer.com.au. This covers all subdomains but not yourmarketer.com.au itself, so add both if you need both.

Allowed domains always use https, so http-only addresses, IP addresses and port numbers are not supported. You can add up to 20 domains.

Images and tracking pixels are not blocked by this list, so they never need a domain added. Your marketing provider can find which domains a tag uses in the browser's developer tools (F12), where blocked requests appear in the Console.

Only add domains you trust and recognise. A domain on this list can load scripts onto your site, so adding one you are unsure about weakens your site's security.

Which setting fixes which problem

What the browser console shows

What it means

What fixes it

"blocked an inline script" or a message suggesting a hash or nonce

A script is running inline code without the security code

The script needs to include the nonce (see How to add the nonce in Google Tag Manager above). Adding a domain will not fix this.

"Refused to load the script" followed by a web address

A tag is loading a script file from a domain that is not allowed

Add that domain to Additional Allowed Domains

"blocked the loading of a resource (connect-src)" or "Refused to connect to" followed by a web address

A tag is trying to send data to a domain that is not allowed

Add that domain to Additional Allowed Domains

"blocked the loading of a resource (frame-src)" or "Refused to frame" followed by a web address

A tag is trying to show content from a domain that is not allowed

Add that domain to Additional Allowed Domains

For the second, third and fourth rows, the web address in the message is the domain to add. For example, in this message the domain to add is track.yourmarketer.com.au:

Refused to connect to 'https://track.yourmarketer.com.au/collect' because it violates the following Content Security Policy directive: "connect-src ..."

What is not supported

  • Running scripts without the nonce. There is no option to turn this off. The nonce has to be added to the script tag itself. If the tool or plugin that creates your tag gives you no way to add an attribute to that script tag, it can't carry the nonce, and the script will be blocked with a "blocked an inline script" message. There is no setting in PracSuite to get around this. Ask your marketing provider whether the tag can be set up another way, for example as a standard Google Tag Manager tag type or a Custom HTML tag that includes the nonce.

  • Blocks from other companies' pages. Some tracking services open their own frames, and any rules inside those frames are set by that service, not by PracSuite. Messages that mention a different policy, such as default-src 'self', usually come from there and cannot be changed in PracSuite.

  • Server-side tagging. A server-side Google Tag Manager endpoint (for example, one hosted on a service such as Stape) can be added as an allowed domain, but because it is on another company's address rather than your own, it will not be treated as first party on a PracSuite page. Most of the usual reasons for using it will not apply. See the note on server-side tagging in Tracking Online Booking Conversions with Google Tag Manager.

Turning custom scripts off

Turn Allow Custom Scripts off and select Save. Your list of allowed domains is kept but is not applied while the setting is off, and applies again if you turn it back on.

Configuration and troubleshooting within Google Tag Manager and other marketing tools is outside Smartsoft's support scope. We can confirm the setting is on and that a domain has been added.

Did this answer your question?