New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CSP: Unintended form submit at CommandButton click #9424
Comments
Have you tested a fix? |
Yes I had |
From here I got the inspiration: https://developer.mozilla.org/en-US/docs/Web/API/Event/cancelable |
OK check out my PR I think it makes sense. |
Indeed. Without CSP would have an inline event handler |
Thanks for the report and the fix! |
Describe the bug
With CSP enabled, form submit event gets triggered after a commandButton is triggered. Two HTTP requests are generated instead of one.
jsWrapper does not manage to cancel the default action of the event. Maybe the
event.cancelable
property should be checked only if available, liketypeof event.cancelable !== 'boolean' || event.cancelable
.Reproducer
Click on the cb2.
Expected behavior
Generate only one HTTP request(for commandButton).
PrimeFaces edition
No response
PrimeFaces version
11.0.0
Theme
No response
JSF implementation
Mojarra
JSF version
2.2.19
Java version
1.8
Browser(s)
Especially on Chrome
The text was updated successfully, but these errors were encountered: