Skip to content

Update CSP for ExamTemplatesController and GroupsController - #8109

Merged
david-yz-liu merged 7 commits into
MarkUsProject:masterfrom
mrafie1:resolve-image-csp-override
Aug 9, 2026
Merged

Update CSP for ExamTemplatesController and GroupsController#8109
david-yz-liu merged 7 commits into
MarkUsProject:masterfrom
mrafie1:resolve-image-csp-override

Conversation

@mrafie1

@mrafie1 mrafie1 commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Proposed Changes

  • Removed :blob CSP exception for images in app/controllers/exam_templates_controller.rb and app/controllers/groups_controller.rb

** UPDATE AUG 8 **

  • Removed CSP exceptions entirely in exam_templates_controller.rb and groups_controller.rb file. These files now rely on default_src definition in content_security_policy.rb file

Reasoning:

Both controllers take in files (data.fileLink or path) as URLs

_assign_errors.js.erb which displays PDFs for exam_templates_controller

Screenshot 2026-08-05 at 16 08 51

assigns_scans.html.erb which displays PDFs for groups_controller

Screenshot 2026-08-05 at 16 34 52

PDFViewer itself does not convert PDFs into blobs: it keeps the URL.

pdf_viewer.jsx file and its function loadPDFFile

Screenshot 2026-08-05 at 16 12 11

Additionally, when viewing PDF files, they are not converted into "blob" images; they keep their original file link.

Screenshot 2026-08-05 at 15 42 31 Screenshot 2026-08-05 at 16 01 05

Since blob is not being used by PDFViewer and the image is kept as its original link by the exam_templates_controller and `groups_controller, it is safe to remove it from the CSP.

Screenshots of your changes (if applicable)

Type of Change

(Write an X or a brief description next to the type or types that best describe your changes.)

Type Applies?
🚨 Breaking change (fix or feature that would cause existing functionality to change)
New feature (non-breaking change that adds functionality)
🐛 Bug fix (non-breaking change that fixes an issue)
🎨 User interface change (change to user interface; provide screenshots)
♻️ Refactoring (internal change to codebase, without changing functionality) x
🚦 Test update (change that only adds or modifies tests)
📦 Dependency update (change that updates a dependency)
📖 Documentation update (change that updates documentation)
🔧 Internal (change that only affects developers or continuous integration)

Checklist

(Complete each of the following items for your pull request. Indicate that you have completed an item by changing the [ ] into a [x] in the raw text, or by clicking on the checkbox in the rendered description on GitHub.)

Before opening your pull request:

  • I have performed a self-review of my changes.
    • Check that all changed files included in this pull request are intentional changes.
    • Check that all changes are relevant to the purpose of this pull request, as described above.
  • I have added tests for my changes, if applicable.
    • This is required for all bug fixes and new features.
  • I have updated the project documentation, if applicable.
    • This is required for new features.
  • If this is my first contribution, I have added myself to the list of contributors.

After opening your pull request:

  • I have updated the project Changelog (this is required for all changes).
  • I have verified that the pre-commit.ci checks have passed.
  • I have verified that the CI tests have passed.
  • I have reviewed the test coverage changes reported by Coveralls.
  • I have requested a review from a project maintainer.

Questions and Comments

(Include any questions or comments you have regarding your changes.)

@coveralls

coveralls commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

Coverage Report for CI Build 31284455825

Coverage at 90.625% (no base build to compare)

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 51736
Covered Lines: 47904
Line Coverage: 92.59%
Relevant Branches: 2491
Covered Branches: 1239
Branch Coverage: 49.74%
Branches in Coverage %: Yes
Coverage Strength: 129.7 hits per line

💛 - Coveralls

@mrafie1
mrafie1 requested a review from david-yz-liu August 5, 2026 21:39
Comment thread app/controllers/exam_templates_controller.rb Outdated

@david-yz-liu david-yz-liu left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work, @mrafie1! (The coveralls.io uploading was failing for a bit, but I re-ran the job.)

@david-yz-liu
david-yz-liu merged commit edb9d50 into MarkUsProject:master Aug 9, 2026
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants