github / github/secure_headers

nonced tag helpers including nonce directive in csp has potential to break applications

Aperta
#470 17 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Ruby
Stelle
3.2k
Fork
253
Merge medio
19h 11m
PR unite (30g)
1

Descrizione

# Bugs

## Nonced tag helpers including nonce directive in csp has potential to break applications

### Problem

Given an application with inline script tags, and a CSP that allows them with `'unsafe-inline'`, using `nonced_javascript_tag` will cause a nonce directive to appear in the CSP header. Modern browsers will then ignore the `'unsafe-inline'` directive and all other script tags without a nonce will cease to be executed.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.