Live preview does not udpate with Seckit module configured.

Created on 28 February 2025, 3 months ago

Overview

Using XB with Seckit module throws errors in the console and does not allow to update live preview.
Steps to reproduce:

  1. I have created a simple component which has a Heading text
  2. I have added a prop to be able to edit the text
  3. When I add the component to the page there are no errors in the console
  4. When I try to update the heading text, I am seeing errors (see attachment) and the live preview does not update

Error message shows, that we already allow a couple of values in our CSP config, but adding 'unsafe eval' would introduces an XSS vulnerability. I assume there are others who would face the same problem with a similar configuration. (Adding 'unsafe-eval' fixes the problem)

🐛 Bug report
Status

Active

Version

0.0

Component

Page builder

Created by

🇭🇺Hungary attilatilman

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024