Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Accessing the nonce from JavaScript, makes all nonce based CSPs strict-dynamic
(opens in new tab)
(github.com)
1 points
bandamo
3y ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
bandamo
OP
3y ago
Stumbled upon this and seems like a security issue. Why do browser not block the access to the nonce attribute?
j
/
k
navigate · click thread line to collapse