Created on 26 May 2025, 3 months ago

Problem/Motivation

klaro requires the csp policy script-src: unsafe-eval

Steps to reproduce

configure your csp to not allow unsafe-eval and inspect console.

I know that this is not an issue of the drupal module, but the klaro library itself.
There is also a very old issue on github for this. Apparently csp is not a great concern for the klaro team.

Despite this drupal integration being excellent work, I think it is a huge oversight in picking klaro.js for drupal cms.

There are no action to be taken in the drupal module. This ticket is just meant for awareness of this issue. Maybe the maintainers of this module or the drupal cms folks have enough influence to push this topic.

πŸ’¬ Support request
Status

Active

Version

3.0

Component

Miscellaneous

Created by

πŸ‡©πŸ‡ͺGermany woldtwerk Stralibu

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Merge Requests

Comments & Activities

Production build 0.71.5 2024