-
Notifications
You must be signed in to change notification settings - Fork 84
Open
Description
Demanding a CSP based on whitelists and hashes is straight forward. It gets more complicated when demanding nonces. One can hardly tell which nonces to use, nor can one check the strength of used nonces. For example what prevents an embedee from constantly using 'nonce-RANDOM'?
At least for the problem demanding nonces in general, Mike proposed the idea of using placeholders in the Embedding-CSP header.