Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Compatibility with Magento 2.4.5-p8 #156

Open
gianstraf opened this issue Oct 16, 2024 · 0 comments
Open

Compatibility with Magento 2.4.5-p8 #156

gianstraf opened this issue Oct 16, 2024 · 0 comments

Comments

@gianstraf
Copy link

Dear Support,
starting with Adobe Commerce 2.4.5-p8, this module is not compliant with new inline script CSP policy.
More informations here:

Module affected: Gigya\GigyaIM
Blocks affected: gigya_customer_form_login, GigyaScript, GigyaModalLogin
Templates: gigya_script.phtml, gigya_login.phtml,
Reason: inclusion of inline scripts is not done through the \Magento\Framework\View\Helper\SecureHtmlRenderer::renderTag method

On installations with CSP Strict Policy activated, the script inclusion is locked and the scripts are not executed.
In browser console: Error: Refused to execute inline script because it violates the following Content Security Policy directive: "script-src

In these conditions, login and registration flow does not work.

Thank you,
Gianluca, Webformat team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant