fix: admin styling to a nonce'd <style> block (CSP is nonce-only) - #4
Merged
Merged
Conversation
…e-only) The admin CSP is nonce-only for style-src (no 'unsafe-inline'), so the inline style="" attributes on the Commerce admin page were being DROPPED by the browser — the status-pill colours never applied and the multi-column form/filter layout collapsed on the live admin. Emit one nonce-carrying <style> block per render (the page handler already receives the CSP nonce as its 2nd arg) and replace every inline style= with a class. The pill tone classes are generated from STATUS_TONE, so a status and its theme-token colours stay defined in one place and remain dark-safe. Tests: a new guard asserts a <style nonce=…> block is emitted and NO inline style= attribute survives, plus the pill tone resolves from theme tokens inside the block. 27 tests green; PHPStan + php-cs-fixer clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The admin CSP is nonce-only for
style-src(SecurityHeaders, no'unsafe-inline'), so the inlinestyle=""attributes on the Commerce admin page were dropped by the browser — status-pill colours never applied and the multi-column form/filter layout collapsed on the live admin. (The coreCspNonceTestguards core templates for exactly this, but plugin HTML isn't scanned, so it slipped through Phase 1/2.)Fix
<style>block per render (the page handler already receives the CSP nonce as its 2nd arg; mirrors coreDemoBanner/PreviewBanner), and replace every inlinestyle=with a class.STATUS_TONE, so each status and itsvar(--nb-*-bg/-text)colours stay defined once and remain dark-safe.Tests
New guard: a
<style nonce=…>block is emitted and no inlinestyle=attribute survives (/\sstyle\s*=/), plus the pill tone resolves from theme tokens inside the block. 27 tests green; PHPStan + php-cs-fixer clean.Paired with the same fix in plugin-inventory. Redeploy will make the pills actually colour on the demo.
🤖 Generated with Claude Code