Skip to content

content-security-policy #213

Description

@lausberg-ac

Under Typo3 Version 12 Content-Security-Policy is active by default.
This Extension uses inline Javascript to create the map. So for CSP you habe to add inline or unsafe-inline in the headers.

I have the Problem, that I have a Hash in my CSP-Header and the Browser says:
Note that 'unsafe-inline' is ignored if either a hash or nonce value is present in the source list.

The Javascript-Call has to be moved into a File called with parameters.

Activity

  1. albig commented on Jul 9, 2025

    @albig
    Collaborator

    I use TYPO3 12.4 on https://osm.bigga.de and CSP is not active by default, if I'm not wrong:

    Image

    If I switch it on, the map isn't shown, and I find in the developer console:

    Content-Security-Policy: Die Einstellungen der Seite haben die Ausführung eines Inline-Skripts (script-src-elem) blockiert, da es gegen folgende Direktive verstößt: "script-src 'self' data: https://*.openstreetmap.org 'report-sample'"
    

    This seems to be the same problem as you found.

    As the JavaScript is created dynamically depending on your settings, it will be not easy to save it in an external file. Has TYPO3 some magic for this? I'm not sure.

  2. lausberg-ac commented on Jul 10, 2025

    @lausberg-ac
    Author

    I've got a solution for this:

    In Template-File
    <f:asset.script identifier="ODS-OSM" src="EXT:ods-osm/Resources/Public/JavaScript/Src/load.js" parameter1="{value1}" parameter2="{value2}"></f:asset.script>

    Or on rendering in Class $script = "<script parameter1='[value1]' parameter2='[value2]' src='load.js'></script>"
    In the Javascript, you can get those parameters by
    parameter1 = document.currentScript.getAttribute('parameter1'); parameter2 = document.currentScript.getAttribute('parameter2');
    Greetings
    Michael

  3. added this to the 5.0.0 milestone on Jul 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions