This is a migrated thread and some comments may be shown as answers.

Kendo elements not working without unsafe-eval

1 Answer 294 Views
General Discussions
This is a migrated thread and some comments may be shown as answers.
Karina
Top achievements
Rank 1
Karina asked on 10 Dec 2019, 12:17 PM

Hello, are you planning to remove the unsafe-eval as part of the content security policy?

 

In this documentation is saying that this is required

https://docs.telerik.com/kendo-ui/troubleshoot/content-security-policy

We need to remove this option from our website and we can't due Kendo library. Are you going to change this requirement in some of the upcoming version?
Thanks,


Ianko
Telerik team
commented on 01 Dec 2021, 09:35 AM

The feature request (https://feedback.telerik.com/kendo-jquery-ui/1359789-csp-support) is still in Unplanned status and there is no target date when we are going to evaluate if removing the unsafe-eval is doable. 

1 Answer, 1 is accepted

Sort by
0
Petar
Telerik team
answered on 12 Dec 2019, 10:59 AM

Hi Karina,

At this time we don't have plans for changing the currently used Content security policy. 

You can read more details about our CSP Support in the following link: https://feedback.telerik.com/kendo-jquery-ui/1359789-csp-support .

Regards,
Petar
Progress Telerik

Get quickly onboarded and successful with your Telerik and/or Kendo UI products with the Virtual Classroom free technical training, available to all active customers. Learn More.
Henning
Top achievements
Rank 1
commented on 29 Nov 2021, 11:06 AM | edited

Hello,

our company is developing a digital gateway for government authorities and our customers are demanding the usage of the content security policy header in our application. Due to a recent change in our customer’s security policies, we are no longer allowed to use the unsafe-eval keyword in the HTML header. Is it possible to use Kendo UI MVC or parts of Kendo UI jQuery/MVC without the usage of unsafe-eval? Or are we forced to search for a replacement of KendoUI jQuery/MVC?

Thanks

Martin
Telerik team
commented on 19 Feb 2024, 08:01 AM

Hello,

With the R1 2023 release, you no longer need to use unsafe-eval. However, in order to achieve CSP compatibility, you will need to make sure that any templates you are using in your project are re-written as per the guide in the CSP-Compatible templates article:

https://docs.telerik.com/kendo-ui/intro/widget-basics/content-security-policy

https://docs.telerik.com/kendo-ui/framework/templates/get-started-csp-templates

Let me know if you have any further questions.

Tags
General Discussions
Asked by
Karina
Top achievements
Rank 1
Answers by
Petar
Telerik team
Share this question
or