Skip to content

Conversation

@BillBuilt
Copy link
Contributor

@BillBuilt BillBuilt commented Sep 24, 2025

This adds support for nonces via templ.GetNonce(ctx)

@indaco
Copy link
Owner

indaco commented Sep 25, 2025

Thanks for submitting this

I have one doubt.

While I can see the value of using GetNonce on script templates - https://templ.guide/security/content-security-policy/#nonces - it is unclear to me why on "style" tags.

I do not remember of CSS styles in goaster used to load or request resources or potentially execute client side code.

What's your opinion?

@smithcoin
Copy link

Allowing the nonce on all tags allows for a more restrictive CSP.

@indaco indaco merged commit b986e0d into indaco:main Sep 28, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants