Skip to content

Consider having ContentSecurityPolicyHeaderWriter supply a script nonce #10826

Description

@jzheaux

In order to have inline scripts and use a strict CSP, it's important to provide a nonce.

Spring Security's ContentSecurityPolicyHeaderWriter could generate a nonce if a {nonce} placeholder is in the policy directive configuration.

Then, it could be made available as a request attribute for use in views.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

in: webAn issue in web modules (web, webmvc)type: enhancementA general enhancement

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions