-
-
Notifications
You must be signed in to change notification settings - Fork 2.1k
security: avoid CSP conflict with sha/nonce during dev & add support for 'style-src-elem' #11562
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
🦋 Changeset detectedLatest commit: 98271f7 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Co-authored-by: Ben McCann <[email protected]>
thank you! |
If |
this is a continuation from #11485, which solved sveltekit related problems to CSP.
after updating sveltekit i tried to remove
unsafe-inline
fromscript-src-elem
,style-src-attr
&style-src-elem
. it worked onscript-src-elem
, butstyle-src-attr
andstyle-src-elem
are not working. this is because of how svelte works with csp (sveltejs/svelte#7800).to combat some the
style-src-elem
i've extended CSP so it automatically adds the SHA for the/* empty */
value if not already added tostyle-src-elem
.i'm not quite sure how
style-src-attr
should be fixed, i believe this has to be done via Svelte with CSSOM.extra: i've also made it so that CSP removes hashes and nonces from
style-src
,style-src-attr
orstyle-src-elem
during dev when adding the "unsafe-inline" to solve this error message:i noticed this after adding the hash myself on my app when trying to solve the
style-src-elem
bug.Please don't delete this checklist! Before submitting the PR, please make sure you do the following:
Tests
pnpm test
and lint the project withpnpm lint
andpnpm check
Changesets
pnpm changeset
and following the prompts. Changesets that add features should beminor
and those that fix bugs should bepatch
. Please prefix changeset messages withfeat:
,fix:
, orchore:
.Edits
Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.