Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Don't penalize 'unsafe-inline' if hash or nonce source is used in 'style-src' part of CSP #277

Closed
fmeum opened this issue Sep 22, 2017 · 0 comments · Fixed by #290
Closed

Comments

@fmeum
Copy link
Contributor

fmeum commented Sep 22, 2017

According to CSP Level 2, 'unsafe-inline' in 'script-src' or 'style-src' will be ignored if a hash or nonce source is used. This is quite convenient as one can maintain backwards compatibility without sacrificing security in modern user agents. Observatory no longer shows a warning for this in the case of 'script-src' since Issue #88 has been closed, but in 'style-src' it still does.

fmeum added a commit to fmeum/http-observatory that referenced this issue Oct 21, 2017
fmeum added a commit to fmeum/http-observatory that referenced this issue Dec 6, 2017
fmeum added a commit to fmeum/http-observatory that referenced this issue Dec 6, 2017
@april april closed this as completed in #290 Dec 6, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant