Skip to content

51D Docs: Fix for Call to eval-like DOM function - #15521

Merged
patmmccann merged 2 commits into
masterfrom
finding-autofix-3067
Aug 31, 2026
Merged

patmmccann merged 2 commits into
masterfrom
finding-autofix-3067

Conversation

@patmmccann

Copy link
Copy Markdown
Collaborator

General fix: replace document.write with DOM node creation (document.createElement, setAttribute) and insertion into <head>, so no HTML string is parsed/executed.

Best concrete fix here: in integrationExamples/gpt/51DegreesRtdProvider_pageIntegration_example.html, replace the document.write(...) block (lines 16–19 in the snippet) with code that:

  1. Builds the Delegate-CH content string exactly as before.
  2. Creates a <meta> element.
  3. Sets http-equiv="Delegate-CH" and content=... via attributes.
  4. Appends it to document.head (or fallback to the first <head> tag).

No new imports or dependencies are needed.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@patmmccann patmmccann changed the title Fix for Call to eval-like DOM function 51D Docs: Fix for Call to eval-like DOM function Aug 24, 2026
@patmmccann

Copy link
Copy Markdown
Collaborator Author

@justadreamer this and one other place in your integration example are generating codeql flags

@barecheck

barecheck Bot commented Aug 24, 2026 •

Copy link
Copy Markdown

Barecheck - Code coverage report

Total: 91.24%

Your code coverage diff: 0.00% ▴

✅ All code changes are covered

@patmmccann
patmmccann marked this pull request as ready for review August 27, 2026 07:16
@patmmccann
patmmccann merged commit 1e13399 into master Aug 31, 2026
130 checks passed
@patmmccann
patmmccann deleted the finding-autofix-3067 branch August 31, 2026 15:19
steffenmllr pushed a commit to mllrsohn/Prebid.js that referenced this pull request Sep 28, 2026
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant