Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add the nonce: true option for stylesheet_link_tag helper #50591

Merged

Conversation

akhilgkrishnan
Copy link
Member

@akhilgkrishnan akhilgkrishnan commented Jan 5, 2024

Motivation / Background

#46141 added the style-src to the default nonce_directives. The javascript_tag and 'javascript_include_tagacceptsnonce: true` option to generate nonce automatically for CSP.

Detail

Add the nonce: true option for stylesheet_link_tag helper to support automatic nonce generation for Content Security Policy. Works the same way as previously introduced javascript_include_tag nonce: true does.

@ajesler Adding you as a co-author since you were worked on this feature previously.

Checklist

Before submitting the PR make sure the following are checked:

  • This Pull Request is related to one change. Changes that are unrelated should be opened in separate PRs.
  • Commit message has a detailed description of what changed and why. If this PR fixes a related issue include it in the commit message. Ex: [Fix #issue-number]
  • Tests are added or updated if you fix a bug or add a feature.
  • CHANGELOG files are updated for the changed libraries if there is a behavior change or additional feature. Minor bug fixes and documentation changes should not be included.

@akhilgkrishnan akhilgkrishnan force-pushed the add-nonce-stylesheet-link-tag branch 2 times, most recently from 92c5cca to 65f131a Compare January 5, 2024 07:22
This provides a shortcut for setting a Content Security Policy nonce on
a stylesheet_link_tag.

Co-authored-by: AJ Esler <ajesler@users.noreply.github.com>
@rafaelfranca rafaelfranca merged commit 8c4af05 into rails:main Jan 5, 2024
4 checks passed
@akhilgkrishnan akhilgkrishnan deleted the add-nonce-stylesheet-link-tag branch January 5, 2024 16:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants