Skip to content

[Content Security] Move inline event handlers into Stimulus controllers - #15080

Closed
manu-gurudath wants to merge 1 commit into
mainfrom
csp-inline-event-handlers
Closed

manu-gurudath wants to merge 1 commit into
mainfrom
csp-inline-event-handlers

Conversation

@manu-gurudath

@manu-gurudath manu-gurudath commented Sep 19, 2026

Copy link
Copy Markdown
Member

Superseded — split further into 15 smaller PRs, one per controller. Closing in favour of:

#15098, #15099, #15100, #15101, #15102, #15103, #15104, #15105, #15106, #15107, #15108, #15109, #15110, #15111, #15112

All fifteen are independent of each other.

Original: #14811

🤖 Generated with Claude Code

https://claude.ai/code/session_01A8Q14mneHoqkzhDrgWFBFN

Replaces every `on*=` attribute left in the views, plus the
`href="javascript:void(0)"` links, with `data-action` bindings on small
Stimulus controllers. The three `onsubmit="onSubmit()"` attributes on the
user forms just go: nothing has defined `onSubmit` for a while.

No CSP header change here: this is part of what `script-src` needs before
it can drop `'unsafe-inline'`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A8Q14mneHoqkzhDrgWFBFN
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants