[LIVY-1088] Update of frontend libs to resolve unnecessary CVE scanner warnings - #563
idzikovsky wants to merge 7 commits into
Conversation
|
Thank you for sharing your changes @idzikovsky, this is a significant UI modernization step. I will leave the PR open for a few days for further comments and I will compare the checksums to the official releases before merging. I am wondering if it is possible to make this work without relaxing the Content-Security-Policy defaults though. During your testing, what was not working with the original CSP? Are both CSP changes ( |
|
Sure, @gyogal, those CSP changes are not crucial. I was checking if anything broke after the update of Bootstrap to a newer major version and noticed that the progress bar for completed statements does not take full width even when its set to 100%. During investigation I've noticed two error messages in the browsers development tools: And a 2nd: So the progress bar was broken because currently its width is set as an inline style here: Which does not work without the And as for another error, it seems like the DataTables uses Here is the screenshot with the current Content Security Policies: And here is the screenshot with the fix: Should I remove that changes from my PR or should we keep the fix? |
|
Thanks a lot for explaining the rendering issues you found during testing with the original CSP. Both of those issues seem fixable. I searched around and an idea for the workaround can be to add the percentage to the progress bars in a new, custom attribute in These could be done in a follow-up "CSP hardening" ticket as well, since this ticket's main scope is to upgrade JS libraries. Maybe we could check if Claude can figure out the workarounds. Please let me know what you think! |
This reverts commit c66a65a.
|
@gyogal I did a little bit more investigation and it appears that the problem with the It should be possible to fall back to the default .custom-select {
appearance: auto;
background: #fff;
padding-right: .75rem;
}Which also should help to get rid of the CSP warning about As for the "width" problem, I think it should be possible to do what you have proposed. |
|
Here is the 2nd PR: I've reverted the CSP changes in this PR in the latest commit here. |
|
Thank you @idzikovsky! It's great that you were able to solve it without changing the CSP. I think it may be better to merge the changes in #564 into this PR, so if somebody just cherry-picks a single change, the UI will be fully functional with the upgraded libraries and no temporary bugs or broken state is introduced at any point. In an upcoming change the CSP could be further hardened using Claude, but that is just a future improvement idea independent of this PR. Thanks again for your work on this and please let me know your thoughts on whether #564 could be merged into this. |
[LIVY-1088] Fix Web UI progress bar and select styling blocked by default CSP
|
@gyogal |



What changes were proposed in this pull request?
#560
https://issues.apache.org/jira/browse/LIVY-1088 - Update of frontend libs to resolve unnecessary CVE scanner warnings
Since it is not a good practice to accept PRs with minified lib updates from anyone in community, I will provide all links to the libraries I've updated so maintainers should be able to verify checksums, or alternatively it should be OK for you to update libraries by yourself, and just cherry-pick this commit to update HTML templates work with Bootstrap 4:
16637db
c66a65a
I took jQuery from here:
Bootstrap from here:
And dataTables from this link:
https://cdn.datatables.net/1.13.11/
How was this patch tested?
Manual sanity check of the Livy UI after all those updates.
Also, I've built Livy with running unit tests.
Was this patch authored or co-authored using generative AI tooling?
Yes.
Generated-by: GitHub Copilot CLI (claude-opus-5.5)