ElMassimo / ElMassimo/vite_ruby

Content security policy for development not working when nonces enabled

Open
#543 1 comment 0 reactions 0 assignees View on GitHub
bug: pending triage
Dominant language
Ruby
Stars
1.6k
Forks
149
Avg merge
5h 13m
Merged PRs (30d)
2

Description

- [x] I have tried upgrading by running `bundle update vite_ruby`.
- [x] I have read the __[troubleshooting section]__ before opening an issue.

### Description πŸ“–

With the following in the Rails content_security_policy.rb:

```ruby
Rails.application.configure do
config.content_security_policy_nonce_generator = ->(_request) { SecureRandom.base64(16) }

config.content_security_policy do |policy|
[SNIP]

if Rails.env.development?
policy.style_src(*policy.style_src, :unsafe_inline)
policy.script_src(*policy.script_src, :unsafe_eval, "http://#{ViteRuby.config.host_with_port}")
policy.connect_src(*policy.connect_src, "ws://#{ViteRuby.config.host_with_port}")
end
end
end
```

styles are broken in development. Getting the following browser console errore:

```
Content-Security-Policy: Ignoring β€œ'unsafe-inline'” within style-src: nonce-source or hash-source specified
```

```
Content-Security-Policy: The page’s settings blocked an inline style (style-src-elem) from being applied because it violates the following directive: β€œstyle-src 'self' https: 'unsafe-inline' 'nonce-hlKBeGISpbxAy7igRiyz2w=='”
```

It appears that, if the CSP contains a nonce, then unsafe-* declarations are ignored. And because of this, all the tags that vite is injecting are not able to load.

When I comment out `content_security_policy_nonce_generator`, then everything works as expected.

### Reproduction 🐞

_Please provide a link to a repo that can reproduce the problem you ran into._

<details>
<summary>Vite Ruby Info</summary>

_Run `bin/rake vite:info` and provide the output:_

```
bin/vite present?: true
vite_ruby: 3.9.2
vite_rails: 3.0.19
rails: 8.0.2
ruby: ruby 3.4.2 (2025-02-15 revision d2930f8e7a) +PRISM [arm64-darwin24]
node: v22.14.0
yarn: 4.8.1

installed packages:
work@ /Volumes/Work
β”œβ”€β”¬ @storybook/svelte-vite@8.6.12
β”‚ β”œβ”€β”¬ @storybook/builder-vite@8.6.12
β”‚ β”‚ └── vite@5.4.18 deduped
β”‚ └── vite@5.4.18 deduped
β”œβ”€β”¬ @sveltejs/vite-plugin-svelte@3.1.2
β”‚ β”œβ”€β”¬ @sveltejs/vite-plugin-svelte-inspector@2.1.0
β”‚ β”‚ └── vite@5.4.18 deduped
β”‚ β”œβ”€β”€ vite@5.4.18 deduped
β”‚ └─┬ vitefu@0.2.5
β”‚ └── vite@5.4.18 deduped
β”œβ”€β”¬ @testing-library/svelte@5.2.7
β”‚ └── vite@5.4.18 deduped
β”œβ”€β”¬ vite-plugin-ruby@5.1.1
β”‚ └── vite@5.4.18 deduped
β”œβ”€β”€ vite@5.4.18
└─┬ vitest@3.1.1
β”œβ”€β”¬ @vitest/mocker@3.1.1
β”‚ └── vite@6.2.6 deduped
β”œβ”€β”¬ vite-node@3.1.1
β”‚ └── vite@6.2.6
└── vite@6.2.6
```
</details>

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.