feat: Provide CSP nonce as `<meta>` element
This way we use the CSP nonce for dynamically loaded scripts. Important to notice: The CSP nonce must NOT be injected in `content` as this can lead to value exfiltration using e.g. side-channel attacts (CSS selectors). Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de>pull/43573/head
parent
009761be58
commit
2916e5df7e
Loading…
Reference in New Issue