Skip to content

Commit 7e77803

Browse files
authored
Merge pull request #263 from jurre/patch-1
Correct usage of content_security_policy_nonce in upgrade docs
2 parents 7604b5b + d113f43 commit 7e77803

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

upgrading-to-3-0.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ Changes
88
| Global configuration | `SecureHeaders::Configuration.configure` block | `SecureHeaders::Configuration.default` block |
99
| All headers besides HPKP and CSP | Accept hashes as config values | Must be strings (validated during configuration) |
1010
| CSP directive values | Accepted space delimited strings OR arrays of strings | Must be arrays of strings |
11-
| CSP Nonce values in views | `@content_security_policy_nonce` | `content_security_policy_script_nonce` or `content_security_policy_style_nonce` |
11+
| CSP Nonce values in views | `@content_security_policy_nonce` | `content_security_policy_nonce(:script)` or `content_security_policy_nonce(:style)` |
1212
| nonce is no longer a source expression | `config.csp = "'self' 'nonce'"` | Remove `'nonce'` from source expression and use [nonce helpers](https://github.com/twitter/secureheaders#nonce). |
1313
| `self`/`none` source expressions | Could be `self` / `none` / `'self'` / `'none'` | Must be `'self'` or `'none'` |
1414
| `inline` / `eval` source expressions | Could be `inline`, `eval`, `'unsafe-inline'`, or `'unsafe-eval'` | Must be `'unsafe-eval'` or `'unsafe-inline'` |

0 commit comments

Comments
 (0)