ACSD-60788: Custom scripts for Google Tag Manager are not executed due to Content Security Policy…
Custom scripts for Google Tag Manager are not executed due to Content Security Policy (CSP) errors. Quality patch ACSD-60788 for magento/module-csp applies to Magento Open Source and Adobe Commerce 2.4.7 to 2.4.7-p10.
- Categories
- Other
- Components
- magento/module-csp, magento/module-google-tag-manager
- Origin
- adobe-commerce-support
- Since QPT
- 1.1.52
Issue
Custom scripts for Google Tag Manager are not executed due to Content Security Policy (CSP) errors.
Steps to reproduce
1. Set up the Google Tag Manager variable. 1. Set up the Google Tag Manager Custom HTML Tag. 1. Place the following JavaScript code in the first Tag: <script nonce="{{gtmNonce}}"> console.log("Nonce from simple JS {{gtmNonce}}"); </script> 1. Flush caches after setting up the GTM. 1. Open the developer console in your browser. 1. Open the Home Page.
Adobe's page lists 2.4.7 - 2.4.7-p3 as compatible; the versions below are resolved from the current QPT constraints and are the ones the tool will offer.
Adobe scheduled the permanent fix for 2.4.8.
Install
Install the Quality Patches Tool with composer require magento/quality-patches, apply the prerequisites listed for all files applicable to your distribution and version first, then run vendor/bin/magento-patches apply ACSD-60788. On Cloud, add ACSD-60788 under stage.build.QUALITY_PATCHES in .magento.env.yaml.
For cweagans/composer-patches, choose a compatible version below and download the bundle. Copy its ACSD-60788/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Bundle prerequisites the same way and list them first. Paths are relative to each package root, using the default -p1 level. Prefer local files when configuring composer-patches; a remote URL can change.
Patch files and compatible versions
magento/magento2-base >=2.4.7 <2.4.8
- Magento Open Source
- 2.4.7-p10, 2.4.7-p9, 2.4.7-p8, 2.4.7-p7, 2.4.7-p6, 2.4.7-p5, 2.4.7-p4, 2.4.7-p3, 2.4.7-p2, 2.4.7-p1, 2.4.7
- Adobe Commerce
- 2.4.7-p10, 2.4.7-p9, 2.4.7-p8, 2.4.7-p7, 2.4.7-p6, 2.4.7-p5, 2.4.7-p4, 2.4.7-p3, 2.4.7-p2, 2.4.7-p1, 2.4.7
- Patch file
- patches/os/ACSD-60788_2.4.7-p1.patch
- vendor/magento/module-csp/ViewModel/NonceProvider.php (added)
- vendor/magento/module-csp/view/base/requirejs-config.js (added)
- vendor/magento/module-csp/view/base/templates/nonce/nonce.phtml (added)
- vendor/magento/module-csp/view/base/web/js/nonce-injector.js (added)
magento/magento2-ee-base >=2.4.7 <2.4.8
- Magento Open Source
- —
- vendor/magento/module-google-tag-manager/view/frontend/layout/default.xml
