You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
DB (MySQL etc.): 11.0.2-MariaDB-1:11.0.2+maria~ubu2204
PHP version: 8.1.21 (fpm-fcgi)
SMW version: 4.1.1
SRF version: 4.1.0-beta
Issue
Datatables v2 does not render when $wgCSPHeader['useNonces'] is set to true. It appears that the inline script added by ResourceFormatter.php does not include an nonce (nonce param in ResourceLoader::makeInlineScript is set to false (#397)).
Steps to reproduce
Set $wgCSPHeader['useNonces'] to true in LocalSettings.php
* Allow for NONCEs on inline scripts
In order to support CSP-Header.
See also
* 6e62a00
* #785
* Remove explicit removal of NONCEs
---------
Co-authored-by: rvogel <vogel@hallowelt.biz>
Setup
Issue
Datatables v2 does not render when
$wgCSPHeader['useNonces']
is set to true. It appears that the inline script added by ResourceFormatter.php does not include an nonce (nonce param inResourceLoader::makeInlineScript
is set tofalse
(#397)).Steps to reproduce
$wgCSPHeader['useNonces']
totrue
in LocalSettings.phpformat=datatables
in an ask inline queryPotential solution
ResourceLoader::makeInlineScript
should include an nonce instead of setting it to false.The text was updated successfully, but these errors were encountered: