Skip to content

fix(google-maps): avoid inline host style that violates CSP style-src - #33947

Open
froy-clgx wants to merge 1 commit into
angular:mainfrom
froy-clgx:patch-1
Open

froy-clgx wants to merge 1 commit into
angular:mainfrom
froy-clgx:patch-1

Conversation

@froy-clgx

Copy link
Copy Markdown

What

MapInfoWindow hides its host element with host: {'style': 'display: none'}. This renders as an inline style attribute on <map-info-window>, which is blocked by a Content Security Policy whose style-src doesn't include 'unsafe-inline'. The browser reports a violation like this for every info window on the page:

Applying inline style violates the following Content Security Policy directive 'style-src ...'

Fix

Remove the host style binding and set display: none on the host element in the constructor through CSSOM (element.style.display). CSP doesn't block CSSOM assignments, so the behavior is unchanged and the directive works under a strict style-src.

Testing

Verified in an app running a strict CSP (style-src without 'unsafe-inline'): before the change, each <map-info-window> raised a CSP violation; after it, none are raised, and the info windows still open and close normally.

@pullapprove
pullapprove Bot requested review from andrewseguin and tjshiu October 9, 2026 15:34
@google-cla

google-cla Bot commented Oct 9, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant