diff options
author | Markus Heiser <markus.heiser@darmarit.de> | 2021-12-05 11:32:04 +0100 |
---|---|---|
committer | Markus Heiser <markus.heiser@darmarit.de> | 2021-12-05 11:48:23 +0100 |
commit | 2b26285a7359f3ad88ce20b3bb925d4593533856 (patch) | |
tree | dff112b21f17a616f3f4b60967911668e59d0d61 /searx/static/themes/simple/js/searxng.min.js.map | |
parent | e4a2d354aa4c0c97a096de47a8bcf6bb22e4d153 (diff) | |
download | searxng-2b26285a7359f3ad88ce20b3bb925d4593533856.tar.gz searxng-2b26285a7359f3ad88ce20b3bb925d4593533856.zip |
[fix] simple theme: make autocomplete-js CSP compliant
The CSP issue is, that the `_Position` function in the autocomplete-js set the
style attributes by `setAttribute("style", ...)`. Using `setAttribute` to set
the style attribute invokes the HTML parser and CSP is triggered [1].
This patch overwrite the `_Position` function of autocomplete-js.
BTW: remove trailing whitespace
[1] https://stackoverflow.com/a/57633533
Closes: https://github.com/searxng/searxng/issues/352
Signed-off-by: Markus Heiser <markus.heiser@darmarit.de>
Diffstat (limited to 'searx/static/themes/simple/js/searxng.min.js.map')
0 files changed, 0 insertions, 0 deletions