Navigation Menu

Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

refactor(csp): remove unsafe-eval in dev mode #7659

Merged
merged 1 commit into from Jul 2, 2020
Merged

Conversation

clarkdo
Copy link
Member

@clarkdo clarkdo commented Jul 2, 2020

Types of changes

  • Bug fix (a non-breaking change which fixes an issue)
  • New feature (a non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)

Description

Follow up #7305 and #7454, now we won't have any eval code if csp is enabled without explicit unsafe-eval config, so we can remove unsafe-eval in dev mode now which will make csp in dev and prod more consistent.

Checklist:

  • My change requires a change to the documentation.
  • I have updated the documentation accordingly. (PR: #)
  • I have added tests to cover my changes (if not applicable, please state why)
  • All new and existing tests are passing.

@clarkdo clarkdo requested a review from pi0 July 2, 2020 17:19
@codecov-commenter
Copy link

Codecov Report

Merging #7659 into dev will not change coverage.
The diff coverage is 100.00%.

Impacted file tree graph

@@           Coverage Diff           @@
##              dev    #7659   +/-   ##
=======================================
  Coverage   70.18%   70.18%           
=======================================
  Files          88       88           
  Lines        3756     3756           
  Branches     1020     1019    -1     
=======================================
  Hits         2636     2636           
  Misses        911      911           
  Partials      209      209           
Flag Coverage Δ
#unittests 70.18% <100.00%> (ø)
Impacted Files Coverage Δ
packages/server/src/middleware/nuxt.js 97.53% <100.00%> (ø)

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update d4363d4...06fff1f. Read the comment docs.

@pi0 pi0 merged commit 0342451 into dev Jul 2, 2020
@pi0 pi0 mentioned this pull request Jul 2, 2020
@pi0 pi0 deleted the remove-unsafe-eval branch September 10, 2020 19:14
@danielroe danielroe added the 2.x label Jan 18, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants