Skip to content

fix(material/progress-bar): avoid CSP issues for apps not using buffer mode #28946

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 24, 2024

Conversation

crisbeto
Copy link
Member

The buffer mode requires an element that uses a data: URI in its styles. This can be problematic for CSP.

Fixes #28938.

…r mode

The `buffer` mode requires an element that uses a `data:` URI in its styles. This can be problematic for CSP.

Fixes angular#28938.
@crisbeto crisbeto removed the request for review from andrewseguin April 24, 2024 14:45
@crisbeto crisbeto added the action: merge The PR is ready for merge by the caretaker label Apr 24, 2024
@crisbeto crisbeto merged commit cf3506a into angular:main Apr 24, 2024
crisbeto added a commit that referenced this pull request Apr 24, 2024
…r mode (#28946)

The `buffer` mode requires an element that uses a `data:` URI in its styles. This can be problematic for CSP.

Fixes #28938.

(cherry picked from commit cf3506a)
@angular-automatic-lock-bot
Copy link

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot bot locked and limited conversation to collaborators May 25, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
action: merge The PR is ready for merge by the caretaker target: patch This PR is targeted for the next patch release
Projects
None yet
Development

Successfully merging this pull request may close these issues.

bug(MatProgressBar): Class, which only works with insecure CSP header, gets applied where not needed
2 participants