github / github/secure_headers
nonced tag helpers including nonce directive in csp has potential to break applications
Open
- Dominant language
- Ruby
- Stars
- 3.2k
- Forks
- 253
- Avg merge
- 19h 11m
- Merged PRs (30d)
- 1
Description
# Bugs
## Nonced tag helpers including nonce directive in csp has potential to break applications
### Problem
Given an application with inline script tags, and a CSP that allows them with `'unsafe-inline'`, using `nonced_javascript_tag` will cause a nonce directive to appear in the CSP header. Modern browsers will then ignore the `'unsafe-inline'` directive and all other script tags without a nonce will cease to be executed.
Contributor guide
Assessment
This issue has not been assessed yet.