-
Notifications
You must be signed in to change notification settings - Fork 40
Open
Description
Nonce reuse
I have a question in regard to nonceEnabled:
I assume that the csp-html-webpack-plugin is only invoked at build time and not for every http request. If this assumption is correct, how can one prevent attackers from just copying CSP nonces and by that bypassing the entire CSP?
Relevant section in the CSP spec is here: https://w3c.github.io/webappsec-csp/#security-nonces
What type of issue is this? (place an x in one of the [ ])
- bug
- enhancement (feature request)
- question
- documentation related
- testing related
- discussion
Requirements (place an x in each of the [ ])
- I've read and understood the Contributing guidelines and have done my best effort to follow them.
- I've read and agree to the Code of Conduct.
- I've searched for any related issues and avoided creating a duplicate issue.
maudnals, Nantris, archfz, MatthiasGwiozda and phallguy
Metadata
Metadata
Assignees
Labels
No labels