Show 'wasm-unsafe-eval' in the default CSP of the security page - #346
Merged
Merged
Conversation
abap2UI5's default script-src now carries 'wasm-unsafe-eval', so a page may compile WebAssembly: SAPUI5's camera scanner (sap.ndc) decodes with it and stopped with a CompileError under the old default. The page shows the policy as shipped and says what the keyword does and does not allow - no string becomes code - and that a policy written in the exit has to keep it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GtaxcT5ECnnEWVeqnY44d5
oblomov-dev
added a commit
that referenced
this pull request
Sep 29, 2026
) abap2UI5/abap2UI5#2809 gave view_display( ) the optional transition and transition_back parameters and added the cs_transition constants. The committed reference still described the interface before that, so check:api-reference failed. That stopped the deploy of the site since the next push (#346). This is npm run generate:api's output, unchanged. Claude-Session: https://claude.ai/code/session_01GtaxcT5ECnnEWVeqnY44d5 Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follows abap2UI5/abap2UI5#2810, which adds
'wasm-unsafe-eval'to the defaultscript-src. SAPUI5's camera scanner (sap.ndc.BarcodeScannerButton) decodes the picture with WebAssembly, and under the old default it stopped with aCompileError.configuration/security.md:script-srcas it will ship.'unsafe-eval'one says what the keyword allows and what it doesn't: a string still never becomes code. It also says that a policy written in the exit has to keep the keyword for the scanner.Merge it together with abap2UI5/abap2UI5#2810 or after it. Until then the page would describe a default that is not shipped yet.
Checked locally:
check:vocabulary,check:line-lengthandnpm test(271 tests) are green. The full site build could not run in this environment, because it fetches the published playground and the proxy here refused it with a 403. CI runs it.🤖 Generated with Claude Code
https://claude.ai/code/session_01GtaxcT5ECnnEWVeqnY44d5