Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-74890

[log-parser] CSP compliance for LogParserWriter

    • 2.3.6

      Problems

      == Inline Script Block (Java)
      File: ./src/main/java/hudson/plugins/logparser/LogParserWriter.java
      Line: 53
      ----
      <script type=\"text/javascript\">\n"
                      + "\tfunction toggleList(list){\n"
                      + "\t\telement = document.getElementById(list).style;\n"
                      + "\t\telement.display == 'none' ? element.display='block' : element.display='none';\n"
                      + "\t}\n" + "</script>
      ----
      
      == Javascript scheme (Java)
      File: ./src/main/java/hudson/plugins/logparser/LogParserWriter.java
      Line: 126
      ----
      "<a href=\"javascript:toggleList('"
      ----
      

      Solutions

      https://www.jenkins.io/doc/developer/security/csp/

          [JENKINS-74890] [log-parser] CSP compliance for LogParserWriter

          Basil Crow created issue -

          Basil Crow added a comment -

          Once the fix for this issue is merged and released, the workaround added in https://github.com/jenkinsci/acceptance-test-harness/issues/1841 should be reverted.

          Basil Crow added a comment - Once the fix for this issue is merged and released, the workaround added in https://github.com/jenkinsci/acceptance-test-harness/issues/1841 should be reverted.
          Basil Crow made changes -
          Assignee Original: Martin Reinhardt [ mreinhardt ]
          Basil Crow made changes -
          Description Original: {noformat}
          == Inline Script Block (Java)
          File: ./src/main/java/hudson/plugins/logparser/LogParserWriter.java
          Line: 53
          ----
          <script type=\"text/javascript\">\n"
                          + "\tfunction toggleList(list){\n"
                          + "\t\telement = document.getElementById(list).style;\n"
                          + "\t\telement.display == 'none' ? element.display='block' : element.display='none';\n"
                          + "\t}\n" + "</script>
          ----

          == Javascript scheme (Java)
          File: ./src/main/java/hudson/plugins/logparser/LogParserWriter.java
          Line: 126
          ----
          "<a href=\"javascript:toggleList('"
          ----
          {noformat}
          New: h3. Problems

          {noformat}
          == Inline Script Block (Java)
          File: ./src/main/java/hudson/plugins/logparser/LogParserWriter.java
          Line: 53
          ----
          <script type=\"text/javascript\">\n"
                          + "\tfunction toggleList(list){\n"
                          + "\t\telement = document.getElementById(list).style;\n"
                          + "\t\telement.display == 'none' ? element.display='block' : element.display='none';\n"
                          + "\t}\n" + "</script>
          ----

          == Javascript scheme (Java)
          File: ./src/main/java/hudson/plugins/logparser/LogParserWriter.java
          Line: 126
          ----
          "<a href=\"javascript:toggleList('"
          ----
          {noformat}

          h3. Solutions

          [https://www.jenkins.io/doc/developer/security/csp/]
          Basil Crow made changes -
          Summary Original: [log parser] CSP compliance for LogParserWriter New: [log-parser] CSP compliance for LogParserWriter
          Yaroslav Afenkin made changes -
          Assignee New: Yaroslav Afenkin [ yafenkin ]
          Yaroslav Afenkin made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]
          Yaroslav Afenkin made changes -
          Status Original: In Progress [ 3 ] New: In Review [ 10005 ]
          Yaroslav Afenkin made changes -
          Remote Link New: This issue links to "jenkinsci/log-parser-plugin/pull/135 (Web Link)" [ 30251 ]
          Yaroslav Afenkin made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: In Review [ 10005 ] New: Fixed but Unreleased [ 10203 ]

            yafenkin Yaroslav Afenkin
            basil Basil Crow
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: