[ 
https://issues.apache.org/jira/browse/OFBIZ-9991?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16262368#comment-16262368
 ] 

Jacques Le Roux commented on OFBIZ-9991:
----------------------------------------

This is due to the CSP policy I put in OFBiz recently. Normally it only reports 
in js console but due to something I changed in FF (not an addon it seems, I 
guess I change something in FF config. Anyway I have just installed 3 others 
CSP related addons :D) it got blocked. 

This is a good news because it seems we have no other case like that, to be 
checked though... And yes attackers can use images: 
https://thehackernews.com/2015/06/Stegosploit-malware.html

> OpenStreetMap geolocation no longer works
> -----------------------------------------
>
>                 Key: OFBIZ-9991
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-9991
>             Project: OFBiz
>          Issue Type: Bug
>          Components: example
>    Affects Versions: Trunk
>            Reporter: Jacques Le Roux
>            Assignee: Jacques Le Roux
>            Priority: Minor
>         Attachments: Screen Shot 2017-11-20 at 19.08.29.png
>
>
> Easily checked at 
> https://demo-trunk.ofbiz.apache.org/example/control/ExampleOsmGeoLocationPointSet1
> It "works" but OpenStreetMap images are not showing. Locally there are no 
> errors in log. So hopefully it could be just an OpenStreetMap setting change 
> we need to do



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

Reply via email to