Skip to content

fix: avoid CSP-blocked runtime initialization - #421

Open
netroms wants to merge 1 commit into
dhis2:masterfrom
netroms:fix/csp-regenerator-runtime
Open

netroms wants to merge 1 commit into
dhis2:masterfrom
netroms:fix/csp-regenerator-runtime

Conversation

@netroms

@netroms netroms commented Sep 25, 2026

Copy link
Copy Markdown

Summary

  • Resolve babel-runtime’s regenerator-runtime to ^0.14.1, avoiding the CSP-blocked global lookup in 0.11 during organisation-unit tree initialization.
  • Scope the dependency override to babel-runtime; no CSP relaxation or generated bundle changes.

Verification

  • 235 tests pass; lint and production build pass.
  • Enforced-CSP browser checks: global-shell entry, reloads/deep links, organisation-unit expansion/selection, Jasper PDF generation, and data-set report/XLS export.

This fixes startup; custom HTML report script policy is unchanged.

AI Assisted

@dhis2/d2-ui-org-unit-tree pulls in babel-runtime 6, which depends on
regenerator-runtime 0.11. Its global lookup falls back to
Function("return this")(), which a Content-Security-Policy without
'unsafe-eval' blocks, so the app fails at startup.

Resolve babel-runtime's regenerator-runtime to ^0.14.1 (already used by
@babel/runtime). 0.14 exports the same mark/wrap API and uses globalThis
before any Function fallback.
@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant