Skip to content

Recaptcha Newsletter still uses inline scripts --> CSP warnings #337

Open
@PachisPachis

Description

Preconditions (*)

1.Magento 2.4.7-p1
2.Default CSP config and whitelisting, no customizations. Please notice that default CSP policies blocks inline scripts in the checkout page.
3.Block for newsletter signup is shown in every page, including checkout. Block has a recaptcha validation.

Steps to reproduce (*)

1.Go to checkout.
2.Check browser console.
3.Notice the CSP warnings, attached screenshots in the following points.

Expected result (*)

  1. Module should use the rendertag function to deal with CSP default requirements, instead of inserting inline scripts. This would allow the script to be executed.
  2. No warnings should be shown by CSP policies in the browser console.

Actual result (*)

  1. Module is inserting inline scripts, detected by the CSP policies and generating unwanted warnings.
    image
    image

2.This is ocurring because of the following code:
image

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions