Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Proposal: Allow nonces? #8

Closed
colinxfleming opened this issue Jun 27, 2017 · 2 comments · Fixed by #10
Closed

Proposal: Allow nonces? #8

colinxfleming opened this issue Jun 27, 2017 · 2 comments · Fixed by #10

Comments

@colinxfleming
Copy link
Contributor

hey, was wondering -- we at DCAF Engineering are interested in using this, but have a pretty strict content security policy that prohibits running inline js without whitelisting it with a sha or a nonce. We was mulling over submitting a PR to this that would take a nonce value as an argument, but wanted to check and make sure this was something you all were interested in first.

If you are, our team can whip something up real quick, if that sounds good to you?

@nikolalsvk
Copy link
Collaborator

@colinxfleming sure thing, we're already generating some kind of unique ID for the container where content gets loaded, maybe that will help.

I'd love to see a pull request dealing with your problem

@colinxfleming
Copy link
Contributor Author

@nikolalsvk sounds good, I'll whip something up in the near term for your thoughts and feedback. Thanks for the quick response!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants