django-crispy-forms / django-crispy-forms/crispy-bootstrap4

CSP issues with file field

Open
#30 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
HTML
Stars
14
Forks
5
PR merge metrics
No merged PRs in 30d

Description

Hi all

The CSP compatibility have already been investigated for [bootstrap 5](https://github.com/django-crispy-forms/crispy-bootstrap5/issues?q=is%3Aissue+csp), and I was wondering if we could also do it for bootstrap 4, I stumbled upon this compatibility issue some weeks ago.

Following [bootstrap doc](https://getbootstrap.com/docs/4.6/components/forms/#file-browser) by using [bs-custom-file-input plugin](https://www.npmjs.com/package/bs-custom-file-input) I was able to remove [the script tag](https://github.com/django-crispy-forms/crispy-bootstrap4/blob/main/crispy_bootstrap4/templates/bootstrap4/layout/field_file.html#L32-L40) (cf #29) and thus make the file field compatible with CSP. My question is whether we should or not remove the script tag as it is a breaking change, all current setup of crispy with custome-file-input and without the plugin will not work visually not work anymore. In a setup with bootstrap 4.3, even with the plugin, the file chosen was not rendered, I had to update to 4.6. Would mentioning in the doc that we have to use boostrap 4.6 and bs-custom-file-input or an equivalent is enough ?

P.S: by csp compatible, I mean without using `unsafe-inline`

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.