Skip to content

[ticket/17649] Pass function reference to setTimeout in progress popup#6995

Open
ECYaz wants to merge 1 commit into
phpbb:masterfrom
ECYaz:ticket/17649
Open

[ticket/17649] Pass function reference to setTimeout in progress popup#6995
ECYaz wants to merge 1 commit into
phpbb:masterfrom
ECYaz:ticket/17649

Conversation

@ECYaz

@ECYaz ECYaz commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Checklist:

  • Correct branch: master for 4.x fixes
  • Tests pass
  • Code follows coding guidelines
  • Commit follows commit message format

Tracker ticket:

https://tracker.phpbb.com/browse/PHPBB-17649

Passing a string to setTimeout is an implicit eval, so a Content Security Policy protecting the ACP has to allow 'unsafe-eval' in script-src just for this one call. Passing the function reference behaves identically — the popup's one-second poll and its self-close when the parent page finishes were verified unchanged on a live board — and lets administrators deploy a stricter policy. This was the only string-argument timer call in the codebase.

Passing a string to setTimeout is an implicit eval, which requires
'unsafe-eval' in a Content Security Policy's script-src directive.
Passing the function reference behaves identically and allows board
administrators to deploy a stricter policy. This was the only string
argument timer call in the codebase.

PHPBB-17649
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant