Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

188804152 script src error on broker registration form #4958

Conversation

bbodine1
Copy link
Contributor

Description of Changes:

Current (incorrect) behavior:
Refused to execute inline event handler because it violates the following Content Security Policy directive: "script-src 'self error message logged

New (correct) behavior:
There should be no Refused to execute inline event handler because it violates the following Content Security Policy directive: "script-src 'self present

Pivotal Ticket Url

Ticket: https://www.pivotaltracker.com/story/show/188804152

PR Type

(Select 1)

  • Bugfix
  • Feature (requires Feature flag)
  • Data fix, Migration, or Report (inert code, no impact until run)
  • Refactoring (no functional changes, no API changes)
  • Build related changes
  • CI related changes
  • Dependency updates (e.g., add a new gem or update to a version)

PR Checklist

Please check if your PR fulfills the following requirements:

  • The title follows our guidelines
  • Tests for the changes have been added (for bug fixes/features), and they use let helpers and before blocks.
  • For all UI changes, there is Cucumber coverage.
  • Any endpoint touched in the PR has an appropriate Pundit policy. For open endpoints, the reasoning is documented in the PR and code.
  • Any endpoint modified in the PR only responds to the expected MIME types.
  • For all scripts or rake tasks, how to run them is documented in both the PR and the code.
  • There are no inline styles added.
  • There is no inline JavaScript added.
  • There is no hard-coded text added/updated in helpers/views/JavaScript. New/updated translation strings do not include markup/styles unless there is supporting documentation.
  • Code does not use .html_safe.
  • All images added/updated have alt text.
  • Does not bypass RuboCop rules in any way.

Feature Flag

For all new feature development, a feature flag is required to control the exposure of the feature to our end users. A feature flag needs a corresponding environment variable to initialize the state of the flag. Please share the name of the environment variable below that would enable/disable the feature and indicate which client(s) it applies to.

Variable name:

  • DC
  • ME

Additional Context

Include any additional context that may be relevant to the peer review process.

@bbodine1 bbodine1 merged commit 5f31aa1 into epic_188588775_csp_enabled Jan 23, 2025
128 checks passed
@bbodine1 bbodine1 deleted the 188804152-script-src-error-on-broker-registration-form branch January 23, 2025 22:05
bbodine1 added a commit that referenced this pull request Jan 24, 2025
* fix: add date validation for staff registration form

* fix: date validation for staff and agency roles in forms

* fix: add key value check for NPN input based on registry feature

* fix: add phone number validation for broker contact information
bbodine1 added a commit that referenced this pull request Jan 28, 2025
* fix: add date validation for staff registration form

* fix: date validation for staff and agency roles in forms

* fix: add key value check for NPN input based on registry feature

* fix: add phone number validation for broker contact information
bbodine1 added a commit that referenced this pull request Jan 31, 2025
* fix: add date validation for staff registration form

* fix: date validation for staff and agency roles in forms

* fix: add key value check for NPN input based on registry feature

* fix: add phone number validation for broker contact information
bbodine1 added a commit that referenced this pull request Feb 4, 2025
* fix: add date validation for staff registration form

* fix: date validation for staff and agency roles in forms

* fix: add key value check for NPN input based on registry feature

* fix: add phone number validation for broker contact information
bbodine1 added a commit that referenced this pull request Feb 5, 2025
* fix: add date validation for staff registration form

* fix: date validation for staff and agency roles in forms

* fix: add key value check for NPN input based on registry feature

* fix: add phone number validation for broker contact information
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants