aidantwoods / aidantwoods/SecureHeaders

Don't warn for 'unsafe-inline' if hash or nonce present in applicable directive

未关闭
#72 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug
主要语言
PHP
星标
433
派生
21
PR 合并指标
30 天内没有已合并 PR

描述

E.g.

https://www.w3.org/TR/CSP2/#directive-script-src
> If 'unsafe-inline' is not in the list of allowed script sources, or if at least one nonce-source or hash-source is present in the list of allowed script sources:[...]

As mentioned in #71.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。