Symptom
An application launched from SAP Build Work Zone (standard or advanced edition) fails to load or renders incompletely. The browser console shows a Content Security Policy (CSP) violation. Chromium-based browsers, for example, report:
Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src * data: blob:".
The issue occurs when the Asynchronous Module Loading option is enabled in the Site Settings.
As of May 16, 2024, Asynchronous Module Loading is enabled by default for newly created sites. Existing sites are not changed automatically unless the setting is edited.
Read more...
Environment
- SAP Build Work Zone
- SAP Fiori
- SAPUI5
Product
Keywords
csp content security policy unsafe eval async asynchronous unsafe-eval content-security-policy , KBA , CA-FLP-FE-UI , SAP Fiori Launchpad User Interface , CA-UI5-COR , Core and Runtime , CA-FLP-FE-COR , SAP Fiori Launchpad Frontend Core and Services , EP-WZ , SAP Build Work Zone , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview