[ 
https://issues.apache.org/jira/browse/WICKET-7172?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18050308#comment-18050308
 ] 

ASF GitHub Bot commented on WICKET-7172:
----------------------------------------

martin-g commented on code in PR #1341:
URL: https://github.com/apache/wicket/pull/1341#discussion_r2667389432


##########
wicket-core/src/main/java/org/apache/wicket/csp/CSPDirective.java:
##########
@@ -147,6 +151,19 @@ public String getValue()
        public void checkValueForDirective(CSPRenderable value,
                        List<CSPRenderable> existingDirectiveValues)
        {
+               if (this == SCRIPT_SRC_ATTR || this == STYLE_SRC_ATTR) 
+               {
+                       if (!existingDirectiveValues.isEmpty()) 
+                       {
+                               throw new IllegalArgumentException("Directive " 
+ this + " supports only one value");

Review Comment:
   Let's hear some more opinions from other CSP users.
   
   My personal opinion is that we should follow the standards but I don't have 
experience in this area.





> Support new CSP style, script directives
> ----------------------------------------
>
>                 Key: WICKET-7172
>                 URL: https://issues.apache.org/jira/browse/WICKET-7172
>             Project: Wicket
>          Issue Type: Improvement
>          Components: wicket-core
>            Reporter: Kees van Dieren
>            Priority: Major
>
> Support new CSP directives added to the CSP in 2022
> They where not yet supported by Wicket.
> See: https://github.com/apache/wicket/pull/1341
>  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to