Conversation
The output of dump() is made of inline scripts and styles, which any policy worth setting blocks, so the dump comes out unstyled and its toggles do not work. The CSP listener now takes the dump data collector, which only the DebugBundle declares, and skips the headers when the response carries at least one dump. This is what WebDebugToolbarListener already does for the policy it manages.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #339, following the pointer you gave there to symfony/symfony@bbb4d9f.
dump()renders as inline scripts and styles, which any policy worth setting blocks, so the dump lands unstyled with dead toggles. TheWebDebugToolbarListenersolved this for the policy it manages by dropping it when the dump collector has something to show; the listener here now does the same.data_collector.dumpis only declared by theDebugBundle, so the reference isNULL_ON_INVALID_REFERENCEand the behaviour cannot reach an environment without it.One detail on the DI side: argument 7 (
request_matcher) was only set conditionally, so appending argument 8 would have left a hole in the array and the collector would have been passed as the request matcher. It is now passed explicitly asnullinsetArguments(), which matches the constructor default, and the conditionalsetArgument(7, ...)below is unchanged.Tests cover both directions: a response with a dump gets no policy, one without keeps it.