Skip to content

[LIVY-1088] Fix Web UI progress bar and select styling blocked by default CSP - #564

Closed
idzikovsky wants to merge 1 commit into
apache:masterfrom
idzikovsky:LIVY-1088b
Closed

idzikovsky wants to merge 1 commit into
apache:masterfrom
idzikovsky:LIVY-1088b

Conversation

@idzikovsky

Copy link
Copy Markdown
Contributor

What changes were proposed in this pull request?

The default livy.server.http.header.Content-Security-Policy does not allow
inline style attributes or data: images (img-src 'self'), which breaks two
parts of the Web UI:

  • Statement progress bars: progressBar() set the width through an inline
    style attribute, which the browser ignores. The width is now stored in a
    data-width attribute and applied through CSSOM (element.style.width) by
    the new applyProgressBarWidths() helper, called from loadStatementsTable().
  • Bootstrap select.custom-select elements: their arrow is a data: SVG
    background image, which is blocked. They now fall back to the browser's
    native <select> appearance.

The default CSP is unchanged.

Screenshot of the Livy UI before the fix:
Screenshot From 2026-10-01 01-03-10

And after the fix:
image

How was this patch tested?

Manually checked the session page and sessions list in a browser with the
default CSP enabled.

Was this patch authored or co-authored using generative AI tooling?

Yes.

Generated-by: GitHub Copilot CLI (claude-opus-5.5)

@idzikovsky

Copy link
Copy Markdown
Contributor Author

This fix will be merged in the scope of #563

@idzikovsky idzikovsky closed this Oct 1, 2026
@idzikovsky
idzikovsky deleted the LIVY-1088b branch October 1, 2026 19:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant