Unplanned
Last Updated: 15 Apr 2025 06:31 by ADMIN
Laurent
Created on: 07 Apr 2025 13:24
Category: PDFViewer
Type: Bug Report
0
PDF Viewer CSP issue

Hi team,

I experience a Content Security Policy issue with the pdf viewer widget.

Dojo: https://dojo.telerik.com/qPYnmOBn

It seems to be dependent of the file though but not quite sure. Try this pdf file : https://www.arcep.fr/uploads/tx_gspublication/referentiel_general_ecoconception_des_services_numeriques_version_2024.pdf

and go to page 20 for instance.

Please advise.

Regards,

Laurent.

3 comments
ADMIN
Neli
Posted on: 15 Apr 2025 06:31

Hello Laurent,

Thank you for the provided additional details. After further review I am converting the current thread from forum to a Bug Report in our Feedback Portal: - https://feedback.telerik.com/kendo-jquery-ui/1684070-pdf-viewer-csp-issue 

Below you wwill find a link also to the related GitHub itemhttps://github.com/telerik/kendo-ui-core/issues/8202.

As a token of gratitude for reporting a bug I have updated your Telerik points. 

Regards,
Neli
Progress Telerik

Enjoyed our products? Share your experience on G2 and receive a $25 Amazon gift card for a limited time!

Laurent
Posted on: 10 Apr 2025 08:08

Hi Neli,

Thank you for your prompt response.

I confirm that on my end the error occurs with different files. 

Furthermore, if you dive into browser dev tools and try to inspect the error you will find that kendo code is dealing with html fragment having inline styles.

Please look the file attached.

Regards,

Laurent

Attached Files:
ADMIN
Neli
Posted on: 10 Apr 2025 07:49

Hi Laurent,

The issue seems related to the styles applied in this specific PDF file. I tested with multiple files on my side, but the issue does not seem to appear. Thus, I assume that there are inline styles in the provided file that are causing the observed issue. Could you please confirm if on your end the error occur with different files?

What we can control is the PDFViewer component to not apply inline styles on the page. However, such scenarios where the issue is caused by specific files are out of our control as we cannot control the uploaded file content.

I remain at your disposal should you have any questions.

Regards,

Neli