aidantwoods / aidantwoods/SecureHeaders
Don't warn for 'unsafe-inline' if hash or nonce present in applicable directive
未关闭
bug
- 主要语言
- PHP
- 星标
- 433
- 派生
- 21
- PR 合并指标
- 30 天内没有已合并 PR
描述
E.g.
https://www.w3.org/TR/CSP2/#directive-script-src
> If 'unsafe-inline' is not in the list of allowed script sources, or if at least one nonce-source or hash-source is present in the list of allowed script sources:[...]
As mentioned in #71.
贡献指南
评估
这个 Issue 还没有评估数据。