Skip to content

Importing DOMPurify results in a CSP violation of inline (“style-src”). #343

@sikorsky555

Description

@sikorsky555

Background & Context

This isn't a huge deal. I haven't noticed any side effects from the CSP violation in Firefox, but when I import DOMPurify, I automatically get a CSP violation in Firefox. I don't have to call a function, just the very nature of importing DOMPurify resulted in the CSP violation.

Bug

Input

N/A

Given output

Content Security Policy: The page’s settings blocked the loading of a resource at inline (“style-src”).

Expected output

No CSP violation

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions