Project

General

Profile

Actions

Bug #27314

open

CSP violation in api accounts custom ACL selection

Added by Clark ANDRIANASOLO about 21 hours ago. Updated about 21 hours ago.

Status:
Pending release
Priority:
N/A
Target version:
Severity:
Major - prevents use of part of Rudder | no simple workaround
UX impact:
User visibility:
Effort required:
Very Small
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No

Description

There are CSP violations due to enabling CSP in all pages in #26934, but some specific AJAX execution and HTML rendering was missing in the API accounts page when editing custom ACLs :


Files

image(2).png (210 KB) image(2).png Clark ANDRIANASOLO, 2025-07-18 15:56

Related issues 2 (2 open0 closed)

Related to Rudder - User story #26951: Plugins need CSP to be strict in Rudder but disabled in plugin pagesPending releaseClark ANDRIANASOLOActions
Related to Rudder - User story #26934: Enable CSP on all pages and add tag to exclude a page Pending releaseFrançois ARMANDActions
Actions #1

Updated by Clark ANDRIANASOLO about 21 hours ago

  • Related to User story #26951: Plugins need CSP to be strict in Rudder but disabled in plugin pages added
  • Related to User story #26934: Enable CSP on all pages and add tag to exclude a page added
Actions #2

Updated by Clark ANDRIANASOLO about 21 hours ago

  • Status changed from New to In progress
Actions #3

Updated by Clark ANDRIANASOLO about 21 hours ago

  • Status changed from In progress to Pending technical review
  • Assignee changed from Clark ANDRIANASOLO to Véronique HAYAERT
  • Pull Request set to https://github.com/Normation/rudder-plugins/pull/873
Actions #4

Updated by Clark ANDRIANASOLO about 21 hours ago

  • Status changed from Pending technical review to Pending release
Actions

Also available in: Atom PDF