Project

General

Profile

Actions

Bug #102460

closed

Incorrect CSP nonce on additional steps and the confirmation message of the form

Added by Benjamin Robinson 6 months ago. Updated 6 months ago.

Status:
Resolved
Priority:
Should have
Assignee:
-
Category:
Form Framework
Target version:
-
Start date:
2023-11-22
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
12
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

Precondition: Feature-Toggle "Security: backend enforce content security policy" on.

With additional form steps, error messages (e.g. when validating a mail address) or the confirmation message of the form, an invalid nonce is sent in the header, so that styles and scripts (e.g. <f:asset.css identifier="background-image" useNonce="1" priority="1">) from the main template of the page no longer work. The "previous button" does not work either.

Tested on TYPO3 12.4.7 + 12.4.8


Related issues 1 (0 open1 closed)

Related to TYPO3 Core - Bug #102438: CSP-Errors after update to 12.4.8Resolved2023-11-21

Actions
Actions

Also available in: Atom PDF