

Suggest a CSP that's compatible with Turbo + import map by dhh · Pull Request #4...
source link: https://github.com/rails/rails/pull/43227
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

In order for CSP to work with Turbo and an import map, we need nonces to be generated, but if we use per-request nonces, we'll cause the default etags generated on the basis of the response html to constantly change. This essentially kills the benefit of our default etags. Seems like it's worth the slight security trade-off to suggest using session-based nonces.
Recommend
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK