Skip to content

Conversation

@iliana
Copy link
Contributor

@iliana iliana commented Apr 15, 2024

Description

createFocusGuard creates a <span>, then applies CSS to it using cssText. This violates Content-Security-Policy unless style-src: 'unsafe-inline' is permitted. Setting the individual properties is acceptable under a strict CSP.

@chaance
Copy link
Member

chaance commented Sep 27, 2024

@iliana I'd like to include this in the next release. Do you mind running yarn version check --interactive so everything is versioned correctly and captured in the changelog?

@iliana
Copy link
Contributor Author

iliana commented Sep 27, 2024

I'm not familiar with yarn, so I'm not sure why this doesn't work:

$ yarn version check --interactive
Usage Error: Your current branch contains multiple versioning files; this isn't supported:
- /Users/iliana/git/primitives/.yarn/versions/19bdd400.yml
- /Users/iliana/git/primitives/.yarn/versions/2ab74363.yml
- /Users/iliana/git/primitives/.yarn/versions/41451f5a.yml
- /Users/iliana/git/primitives/.yarn/versions/5793010b.yml
- /Users/iliana/git/primitives/.yarn/versions/8a3bd6ee.yml
- /Users/iliana/git/primitives/.yarn/versions/96c502e7.yml
- /Users/iliana/git/primitives/.yarn/versions/a0df87d9.yml
- /Users/iliana/git/primitives/.yarn/versions/a54ad5a9.yml
- /Users/iliana/git/primitives/.yarn/versions/c80771b8.yml
- /Users/iliana/git/primitives/.yarn/versions/cc138cf5.yml
- /Users/iliana/git/primitives/.yarn/versions/cccc0adb.yml
- /Users/iliana/git/primitives/.yarn/versions/dc4b1017.yml
- /Users/iliana/git/primitives/.yarn/versions/ded3a040.yml
- /Users/iliana/git/primitives/.yarn/versions/e97b6ff3.yml
- /Users/iliana/git/primitives/.yarn/versions/eb020608.yml
- /Users/iliana/git/primitives/.yarn/versions/f24f9512.yml
- /Users/iliana/git/primitives/.yarn/versions/f4333956.yml
- /Users/iliana/git/primitives/.yarn/versions/fad3e42d.yml

It seems like my yarn version is correct per the value in package.json:

$ yarn --version
4.1.0

@iliana
Copy link
Contributor Author

iliana commented Sep 27, 2024

Evidently the merge from main caused the issue, yarn doesn't seem to be able to handle that. I rebased instead.

Violates Content-Security-Policy unless `style-src: 'unsafe-inline'` is
permitted otherwise.
@chaance chaance merged commit fc53007 into radix-ui:main Sep 27, 2024
@david-crespo david-crespo mentioned this pull request Feb 17, 2025
8 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants