Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add rename_csp_helper_nonce_attribute ActionView configuration to avoid value exfiltration #51729

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Commits on May 14, 2024

  1. Add rename_csp_helper_nonce_attribute actionview configuration

    Adds a configuration to rename the csp helper attribute name.
    
    It's disabled by default currently until the JS libraries are updated to the
    new attribute name and Rails can ship with a new default attribute name.
    
    Fixes rails#51580
    codergeek121 committed May 14, 2024
    Configuration menu
    Copy the full SHA
    68a83a2 View commit details
    Browse the repository at this point in the history