Narrow application of 'unsafe-inline' for quickedit

Created on 12 August 2020, almost 4 years ago
Updated 29 January 2023, over 1 year ago

Problem/Motivation

Since quickedit may load CKEditor on a page via AJAX, it needs to allow script-src-attr 'unsafe-inline'. It is currently done on any request that includes the quickedit library, regardless of the actual content on the page.

Proposed resolution

When quickedit is used, only apply 'unsafe-inline' if there are editable fields that use text formats / CKEditor.

Remaining tasks

✨ Feature request
Status

Closed: won't fix

Version

1.0

Component

Code

Created by

πŸ‡¨πŸ‡¦Canada gapple

Live updates comments and jobs are added and updated live.
  • Security improvements

    It makes Drupal less vulnerable to abuse or misuse. Note, this is the preferred tag, though the Security tag has a large body of issues tagged to it. Do NOT publicly disclose security vulnerabilities; contact the security team instead. Anyone (whether security team or not) can apply this tag to security improvements that do not directly present a vulnerability e.g. hardening an API to add filtering to reduce a common mistake in contributed modules.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.69.0 2024