[openid] Extract inline script block in hudson/plugins/openid/OpenIdLoginService/_openid-form-body.jelly

XMLWordPrintable

    • Type: Task
    • Resolution: Unresolved
    • Priority: Minor
    • Component/s: openid-plugin

      Note

      While testing this plugin, evaluate whether the third-party libraries in src/main/webapp are compatible with CSP in restrictive mode. The plugin may need to be upgraded from jQuery 1.x to 3.x to fully function in CSP restrictive mode.

      Problem

      == Inline Script Block
      Line: 16
      ----
      <script>
            Behaviour.addLoadEvent(function() {
              openid.img_path = '${resURL}/openid-assets/';
              openid.signin_text = "${%Login}";
              openid.init('openid');
              // makeButton($('openid_submit'),openid.submit);
            });
          </script>
      ----
      

      Solution

      https://www.jenkins.io/doc/developer/security/csp/#inline-javascript-blocks

            Assignee:
            Michael Nazzareno
            Reporter:
            Basil Crow
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: