-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Closed
Labels
1. to developAccepted and waiting to be taken care ofAccepted and waiting to be taken care ofenhancementtechnical debt
Description
In #10205 I tried to always add the CSP nonce.
As most browsers if unsafe-inline is there and a nonce will ignore the unsafe-inline. This is the CSPv3 backwards compatibility idea.
However this seems to break on Edge. As edge doesn't properly parse the nonce on external resources.
We should investigate how to enable the nonce on more browsers.
Metadata
Metadata
Assignees
Labels
1. to developAccepted and waiting to be taken care ofAccepted and waiting to be taken care ofenhancementtechnical debt