This way we use the CSP nonce for dynamically loaded scripts. Important to notice: The CSP nonce must NOT be injected in `content` as this can lead to value exfiltration using e.g. side-channel attacts (CSS selectors). Signed-off-by: Ferdinand Thiessen <opensource@fthiessen.de> |
||
|---|---|---|
| .. | ||
| Mock | ||
| BruteForceMiddlewareTest.php | ||
| CORSMiddlewareTest.php | ||
| CSPMiddlewareTest.php | ||
| FeaturePolicyMiddlewareTest.php | ||
| PasswordConfirmationMiddlewareTest.php | ||
| RateLimitingMiddlewareTest.php | ||
| SameSiteCookieMiddlewareTest.php | ||
| SecurityMiddlewareTest.php | ||