Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Fix CspBuilder not applying fallback to uninitialized directive#23855

Merged
MarkEWaite merged 2 commits into
jenkinsci:masterfrom
daniel-beck:fix-uninitialized-fallback
Nov 28, 2025
Merged

Fix CspBuilder not applying fallback to uninitialized directive#23855
MarkEWaite merged 2 commits into
jenkinsci:masterfrom
daniel-beck:fix-uninitialized-fallback

Conversation

@daniel-beck
Copy link
Copy Markdown
Member

Fixes #23854.

Testing done

Autotests

Proposed changelog entries

  • Fix incorrect handling of Content Security Policy inheritance chain for fetch directives. This could affect attempts to set *-src-elemor *-src-attr directives in CSP Plugin 2.x.

Proposed changelog category

/label bug

Proposed upgrade guidelines

N/A

Submitter checklist

  • The issue, if it exists, is well-described.
  • The changelog entries and upgrade guidelines are appropriate for the audience affected by the change (users or developers, depending on the change) and are in the imperative mood (see examples). Fill in the Proposed upgrade guidelines section only if there are breaking changes or changes that may require extra steps from users during upgrade.
  • There is automated testing or an explanation as to why this change has no tests.
  • New public classes, fields, and methods are annotated with @Restricted or have @since TODO Javadocs, as appropriate.
  • New deprecations are annotated with @Deprecated(since = "TODO") or @Deprecated(forRemoval = true, since = "TODO"), if applicable.
  • UI changes do not introduce regressions when enforcing the current default rules of Content Security Policy Plugin. In particular, new or substantially changed JavaScript is not defined inline and does not call eval to ease future introduction of Content Security Policy (CSP) directives (see documentation).
  • For dependency updates, there are links to external changelogs and, if possible, full differentials.
  • For new APIs and extension points, there is a link to at least one consumer.

Desired reviewers

@mention

Before the changes are marked as ready-for-merge:

Maintainer checklist

  • There are at least two (2) approvals for the pull request and no outstanding requests for change.
  • Conversations in the pull request are over, or it is explicit that a reviewer is not blocking the change.
  • Changelog entries in the pull request title and/or Proposed changelog entries are accurate, human-readable, and in the imperative mood.
  • Proper changelog labels are set so that the changelog can be generated automatically.
  • If the change needs additional upgrade steps from users, the upgrade-guide-needed label is set and there is a Proposed upgrade guidelines section in the pull request title (see example).
  • If it would make sense to backport the change to LTS, be a Bug or Improvement, and either the issue or pull request must be labeled as lts-candidate to be considered.

@comment-ops-bot comment-ops-bot Bot added the bug For changelog: Minor bug. Will be listed after features label Nov 25, 2025
@daniel-beck
Copy link
Copy Markdown
Member Author

This PR is now ready for merge. We will merge it after approximately 24 hours if there is no negative feedback. Please see the merge process documentation for more information about the merge process.

/label ready-for-merge

(I'll need someone else to merge this unfortunately, I'm ooo the next few days)

@comment-ops-bot comment-ops-bot Bot added the ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback label Nov 26, 2025
@MarkEWaite MarkEWaite merged commit b641f88 into jenkinsci:master Nov 28, 2025
19 checks passed
karthikbhandary2 pushed a commit to karthikbhandary2/jenkins that referenced this pull request Dec 4, 2025
…insci#23855)

* Fix CspBuilder not applying fallback to uninitialized directive

* Improve test further

---------

Co-authored-by: Daniel Beck <[email protected]>
@daniel-beck daniel-beck deleted the fix-uninitialized-fallback branch December 30, 2025 08:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug For changelog: Minor bug. Will be listed after features ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CspBuilder does not properly handle FetchDirective fallbacks to uninitialized values

4 participants