Skip to content

Show 'wasm-unsafe-eval' in the default CSP of the security page - #346

Merged
oblomov-dev merged 1 commit into
mainfrom
claude/fervent-dirac-supo1k
Sep 29, 2026
Merged

oblomov-dev merged 1 commit into
mainfrom
claude/fervent-dirac-supo1k

Conversation

@oblomov-dev

@oblomov-dev oblomov-dev commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Follows abap2UI5/abap2UI5#2810, which adds 'wasm-unsafe-eval' to the default script-src. SAPUI5's camera scanner (sap.ndc.BarcodeScannerButton) decodes the picture with WebAssembly, and under the old default it stopped with a CompileError.

configuration/security.md:

  • The "Default CSP" block shows script-src as it will ship.
  • A new paragraph after the no-'unsafe-eval' one says what the keyword allows and what it doesn't: a string still never becomes code. It also says that a policy written in the exit has to keep the keyword for the scanner.

Merge it together with abap2UI5/abap2UI5#2810 or after it. Until then the page would describe a default that is not shipped yet.

Checked locally: check:vocabulary, check:line-length and npm test (271 tests) are green. The full site build could not run in this environment, because it fetches the published playground and the proxy here refused it with a 403. CI runs it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GtaxcT5ECnnEWVeqnY44d5

abap2UI5's default script-src now carries 'wasm-unsafe-eval', so a page
may compile WebAssembly: SAPUI5's camera scanner (sap.ndc) decodes with
it and stopped with a CompileError under the old default. The page shows
the policy as shipped and says what the keyword does and does not allow -
no string becomes code - and that a policy written in the exit has to keep
it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GtaxcT5ECnnEWVeqnY44d5
@oblomov-dev
oblomov-dev merged commit 8ab5d78 into main Sep 29, 2026
1 check failed
@oblomov-dev
oblomov-dev deleted the claude/fervent-dirac-supo1k branch September 29, 2026 00:50
oblomov-dev added a commit that referenced this pull request Sep 29, 2026
)

abap2UI5/abap2UI5#2809 gave view_display( ) the optional transition and
transition_back parameters and added the cs_transition constants. The
committed reference still described the interface before that, so
check:api-reference failed. That stopped the deploy of the site since the
next push (#346). This is npm run generate:api's output, unchanged.


Claude-Session: https://claude.ai/code/session_01GtaxcT5ECnnEWVeqnY44d5

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants