SAP Knowledge Base Article - Preview

3789806 - SAP Build Work Zone: CSP 'unsafe-eval' Violation When "Asynchronous Module Loading" Is Enabled

Symptom

An application launched from SAP Build Work Zone (standard or advanced edition) fails to load or renders incompletely. The browser console shows a Content Security Policy (CSP) violation. Chromium-based browsers, for example, report:

Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src * data: blob:".

The issue occurs when the Asynchronous Module Loading option is enabled in the Site Settings.

As of May 16, 2024, Asynchronous Module Loading is enabled by default for newly created sites. Existing sites are not changed automatically unless the setting is edited.


Read more...

Environment

  • SAP Build Work Zone
  • SAP Fiori
  • SAPUI5

Product

SAP BTP, Cloud Foundry runtime and environment all versions ; SAP Fiori all versions ; UI5 automation framework all versions

Keywords

csp content security policy unsafe eval async asynchronous unsafe-eval content-security-policy  , KBA , CA-FLP-FE-UI , SAP Fiori Launchpad User Interface , CA-UI5-COR , Core and Runtime , CA-FLP-FE-COR , SAP Fiori Launchpad Frontend Core and Services , EP-WZ , SAP Build Work Zone , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.