ionic-team / ionic-team/ionicons
bug: CSP - Refused to apply inline style because it violates the following Content Security Policy directive: "style-src-elem …"
- Lingua principale
- TypeScript
- Stelle
- 18.2k
- Fork
- 2.1k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
### Current Behavior
When you enable at least the following CSP header
```
Content-Security-Policy = 'default-src https://cdnjs.cloudflare.com/ajax/libs; style-src-elem https://cdnjs.cloudflare.com/ajax/libs'
```
browsers will refuse to apply inline styles (rightfully).
The exact error message:
```
p-ea7bbed1.system.js:1 Refused to apply inline style because it violates the following Content Security Policy directive: "style-src-elem localhost […]". Either the 'unsafe-inline' keyword, a hash ('sha256-NBfyYgxoWTkJ9SyHWLNVIq8UkKGvsaGPAaGmNMpVMSA='), or a nonce ('nonce-...') is required to enable inline execution.
```
Problematic code (in the last line):
```js
{
$.innerHTML = n + v;
$.setAttribute("data-styles", "");
l.insertBefore($, o ? o.nextSibling : l.firstChild)
}
```
File: https://cdnjs.cloudflare.com/ajax/libs/ionicons/7.1.0/ionicons/p-ea7bbed1.system.js
### Expected Behavior
Styles applied normally from JS and not inline.
### Steps to Reproduce
Turn on the mentioned CSP headers.
### Code Reproduction URL
_No response_
### Additional Information
_No response_
Guida per i contributori
Apri la guida per i contributori
Valutazione
Questa issue non è ancora stata valutata.