Skip to content

CSP nonce by default #10207

@rullzer

Description

@rullzer

In #10205 I tried to always add the CSP nonce.

As most browsers if unsafe-inline is there and a nonce will ignore the unsafe-inline. This is the CSPv3 backwards compatibility idea.

However this seems to break on Edge. As edge doesn't properly parse the nonce on external resources.

We should investigate how to enable the nonce on more browsers.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions