django-crispy-forms / django-crispy-forms/crispy-bootstrap4
CSP issues with file field
- Dominant language
- HTML
- Stars
- 14
- Forks
- 5
- PR merge metrics
- No merged PRs in 30d
Description
Hi all
The CSP compatibility have already been investigated for [bootstrap 5](https://github.com/django-crispy-forms/crispy-bootstrap5/issues?q=is%3Aissue+csp), and I was wondering if we could also do it for bootstrap 4, I stumbled upon this compatibility issue some weeks ago.
Following [bootstrap doc](https://getbootstrap.com/docs/4.6/components/forms/#file-browser) by using [bs-custom-file-input plugin](https://www.npmjs.com/package/bs-custom-file-input) I was able to remove [the script tag](https://github.com/django-crispy-forms/crispy-bootstrap4/blob/main/crispy_bootstrap4/templates/bootstrap4/layout/field_file.html#L32-L40) (cf #29) and thus make the file field compatible with CSP. My question is whether we should or not remove the script tag as it is a breaking change, all current setup of crispy with custome-file-input and without the plugin will not work visually not work anymore. In a setup with bootstrap 4.3, even with the plugin, the file chosen was not rendered, I had to update to 4.6. Would mentioning in the doc that we have to use boostrap 4.6 and bs-custom-file-input or an equivalent is enough ?
P.S: by csp compatible, I mean without using `unsafe-inline`
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.