5

Suggest a CSP that's compatible with Turbo + import map by dhh · Pull Request #4...

 3 years ago
source link: https://github.com/rails/rails/pull/43227
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Copy link

Member

dhh commented 11 days ago

In order for CSP to work with Turbo and an import map, we need nonces to be generated, but if we use per-request nonces, we'll cause the default etags generated on the basis of the response html to constantly change. This essentially kills the benefit of our default etags. Seems like it's worth the slight security trade-off to suggest using session-based nonces.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK