ionic-team / ionic-team/ionicons

bug: CSP - Refused to apply inline style because it violates the following Content Security Policy directive: "style-src-elem …"

Aperta
#1,218 2 commenti 2 reazioni 0 assegnatari Vedi su GitHub
help wanted
Lingua principale
TypeScript
Stelle
18.2k
Fork
2.1k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

### Current Behavior

When you enable at least the following CSP header
```
Content-Security-Policy = 'default-src https://cdnjs.cloudflare.com/ajax/libs; style-src-elem https://cdnjs.cloudflare.com/ajax/libs'
```
browsers will refuse to apply inline styles (rightfully).

The exact error message:
```
p-ea7bbed1.system.js:1 Refused to apply inline style because it violates the following Content Security Policy directive: "style-src-elem localhost […]". Either the 'unsafe-inline' keyword, a hash ('sha256-NBfyYgxoWTkJ9SyHWLNVIq8UkKGvsaGPAaGmNMpVMSA='), or a nonce ('nonce-...') is required to enable inline execution.
```

Problematic code (in the last line):
```js
{
$.innerHTML = n + v;
$.setAttribute("data-styles", "");
l.insertBefore($, o ? o.nextSibling : l.firstChild)
}
```
File: https://cdnjs.cloudflare.com/ajax/libs/ionicons/7.1.0/ionicons/p-ea7bbed1.system.js

### Expected Behavior

Styles applied normally from JS and not inline.

### Steps to Reproduce

Turn on the mentioned CSP headers.

### Code Reproduction URL

_No response_

### Additional Information

_No response_

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.