Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CSP]: Content security policy violations in SVGs #6178

Closed
2 of 5 tasks
amal-k-joy opened this issue Oct 7, 2024 · 2 comments · Fixed by #6202
Closed
2 of 5 tasks

[CSP]: Content security policy violations in SVGs #6178

amal-k-joy opened this issue Oct 7, 2024 · 2 comments · Fixed by #6202
Assignees
Labels
role: dev type: bug 🐛 Something isn't working

Comments

@amal-k-joy
Copy link
Contributor

amal-k-joy commented Oct 7, 2024

Package

Carbon for IBM Products

Description

Violation throwing from the SVGs used inside the empty state component

Component(s) impacted

Datagrid, EmptyState, HTTPError

Browser

Chrome

@carbon/ibm-products (previously @carbon/ibm-cloud-cognitive) version

v2.49.0

Suggested Severity

None

Product/offering

na

CodeSandbox or Stackblitz example

https://stackblitz.com/edit/github-fenvlt-5kkbmk?file=index.html

Steps to reproduce the issue (if applicable)

Run the stackblitz and check the console.
This style is being injected dynamically

Image

Screen.Recording.2024-10-07.at.1.48.37.PM.mov

Release date (if applicable)

No response

Code of Conduct

Tasks

@github-project-automation github-project-automation bot moved this to Needs triage 🧐 in Carbon for IBM Products Oct 7, 2024
@elycheea elycheea changed the title [CSP]: Content security policy violations in Emptystate component [CSP]: Content security policy violations in SVGs Oct 8, 2024
@elycheea elycheea added type: bug 🐛 Something isn't working Sev 2 Aspects of design is broken and impedes users in a significant way, but has workaround. labels Oct 8, 2024
@elycheea elycheea moved this from Needs triage 🧐 to Backlog 🌋 in Carbon for IBM Products Oct 8, 2024
@elycheea elycheea added role: dev and removed Sev 2 Aspects of design is broken and impedes users in a significant way, but has workaround. role: dev labels Oct 8, 2024
@matthewgallo
Copy link
Member

There is some discussion here about the handling of style attributes in svgs from core that could provide some helpful insight.

@AlexanderMelox
Copy link
Contributor

No need to touch deprecated SVG's

@devadula-nandan devadula-nandan moved this from Backlog 🌋 to Needs review 👋 in Carbon for IBM Products Oct 10, 2024
@github-project-automation github-project-automation bot moved this from Needs review 👋 to Done 🚀 in Carbon for IBM Products Oct 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
role: dev type: bug 🐛 Something isn't working
Projects
Status: Done 🚀
Development

Successfully merging a pull request may close this issue.

5 participants