Skip to content

Nonces for Embedding-CSP #121

@dhausknecht

Description

@dhausknecht

Demanding a CSP based on whitelists and hashes is straight forward. It gets more complicated when demanding nonces. One can hardly tell which nonces to use, nor can one check the strength of used nonces. For example what prevents an embedee from constantly using 'nonce-RANDOM'?

At least for the problem demanding nonces in general, Mike proposed the idea of using placeholders in the Embedding-CSP header.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions