To avoid relying on HTML event handlers and adding unsafe-* rules to CSP, the javascript is moved to a <script> tag. This also allows a better browser compatibility
Closes gh-11676
pull/11720/head
Marcus Da Coregio3 years agocommitted byJosh Cummings
@ -237,10 +237,10 @@ public class Saml2WebSsoAuthenticationRequestFilter extends OncePerRequestFilter
@@ -237,10 +237,10 @@ public class Saml2WebSsoAuthenticationRequestFilter extends OncePerRequestFilter
html.append(" <strong>Note:</strong> Since your browser does not support JavaScript,\n");
@ -269,6 +269,7 @@ public class Saml2WebSsoAuthenticationRequestFilter extends OncePerRequestFilter
@@ -269,6 +269,7 @@ public class Saml2WebSsoAuthenticationRequestFilter extends OncePerRequestFilter
@ -216,7 +216,7 @@ public final class Saml2LogoutRequestFilter extends OncePerRequestFilter {
@@ -216,7 +216,7 @@ public final class Saml2LogoutRequestFilter extends OncePerRequestFilter {
@ -248,6 +248,7 @@ public final class Saml2LogoutRequestFilter extends OncePerRequestFilter {
@@ -248,6 +248,7 @@ public final class Saml2LogoutRequestFilter extends OncePerRequestFilter {
@ -120,7 +120,7 @@ public final class Saml2RelyingPartyInitiatedLogoutSuccessHandler implements Log
@@ -120,7 +120,7 @@ public final class Saml2RelyingPartyInitiatedLogoutSuccessHandler implements Log
@ -152,6 +152,7 @@ public final class Saml2RelyingPartyInitiatedLogoutSuccessHandler implements Log
@@ -152,6 +152,7 @@ public final class Saml2RelyingPartyInitiatedLogoutSuccessHandler implements Log
@ -199,8 +199,8 @@ public class Saml2WebSsoAuthenticationRequestFilterTests {
@@ -199,8 +199,8 @@ public class Saml2WebSsoAuthenticationRequestFilterTests {
@ -98,8 +98,8 @@ public class Saml2RelyingPartyInitiatedLogoutSuccessHandlerTests {
@@ -98,8 +98,8 @@ public class Saml2RelyingPartyInitiatedLogoutSuccessHandlerTests {