mirror of https://github.com/docusealco/docuseal
The inline script lacked a nonce and was blocked by the enforced CSP (application_controller#set_csp uses a nonce'd script-src), so the toggle and provider-switching handlers never ran. Add the standard content_security_policy_nonce attribute, matching other inline scripts (e.g. scripts/_autosize_field). Update the two original tests that assumed the provider section is always visible, since it is now correctly hidden when SMS is disabled.pull/687/head
parent
d4c7a22fa2
commit
921f0c6d4b
Loading…
Reference in new issue