-
Notifications
You must be signed in to change notification settings - Fork 125
Backport of CSP-related changes #5606
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: 4.0
Are you sure you want to change the base?
Conversation
|
@arjantijms @BalusC Any thoughts on this? |
|
Thanks for backporting this, first off! Secondly, out of all the changes implemented, I can't seem to find the one addressing the need of Any chance of any of the PR participants to point it out? Thanks in advance for your time! |
|
LGTM :) But why exactly is Issue5576IT disabled? Have you already ran the entire 4.0 TCK on this branch? Did it all pass? (sorry for late response, I was vacationing) |
impl/src/main/resources/META-INF/resources/jakarta.faces/faces-uncompressed.js
Show resolved
Hide resolved
impl/src/main/resources/META-INF/resources/jakarta.faces/faces-uncompressed.js
Outdated
Show resolved
Hide resolved
@fcarriedos Sorry. Work took me away from this for a bit. :) I thought I had ported everything. Can you point to what I missed? Definitely want to make sure we get it all. :) |
test/issue5576/src/test/java/org/eclipse/mojarra/test/issue5576/Issue5576IT.java
Outdated
Show resolved
Hide resolved
|
@jasondlee Thanks for coming back to me on this one! I'm failing to see any specific change to address the issue described below, more specifically in the definition of Please let me know if I missed something, I am looking in the wrong place or any clarification is needed. ContextWhen there is more than one event handler or more than one action per handler, mojarra/impl/src/main/resources/META-INF/resources/jakarta.faces/faces-uncompressed.js Line 3527 in 1ae407c
For this to work, the Content Security Policy forces the need for I pushed this reproducer and I'm attaching some screenshots that hopefully help clarifying the issue.
Thanks in advance for your time! 🙇 |
|
@fcarriedos Thanks. I'll give that a look. My backport is, fwiw, a backport of all of the CSP-related changes from 5.x. I don't pretend to understand all of the changes, but I'll try to fix that. :) |
|
I fixed it in 5.0 #5631 @jasondlee you can now backport thas as well into your branch |
Thanks! On it... |


Backporting CSP-related changes from 5.x to the 4.0 branch.