Skip to content

[TASK] Use nonce in script include for CSP#55

Open
schliesser wants to merge 1 commit intostudiomitte:mainfrom
schliesser:csp-fix
Open

[TASK] Use nonce in script include for CSP#55
schliesser wants to merge 1 commit intostudiomitte:mainfrom
schliesser:csp-fix

Conversation

@schliesser
Copy link

Prevent CSP errors when using the TYPO3 nonce-proxy:

Loading the script 'https://example.com/_assets/99f99e76d2a79baa40bc399c2e8cb79e/JavaScript/lib/sdk@0.1.26-site.compat.min.js?1752835214' violates the following Content Security Policy directive: "script-src 'nonce-nA_v2UZg86NvzQJUKfHNVGFjrqRMGWFCUb0QMe1NWC_-xfyzVt-zsQ' 'strict-dynamic' 'report-sample'". Note that 'strict-dynamic' is present, so host-based allowlisting is disabled.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant