mirror of
https://github.com/discourse/discourse.git
synced 2025-02-25 18:55:32 -06:00
SECURITY: Don't reuse CSP nonce between requests (#22544)
Co-authored-by: OsamaSayegh <asooomaasoooma90@gmail.com>
This commit is contained in:
@@ -25,8 +25,8 @@ class ContentSecurityPolicy
|
||||
style_src
|
||||
].freeze
|
||||
|
||||
def initialize(base_url:)
|
||||
@directives = Default.new(base_url: base_url).directives
|
||||
def initialize(base_url:, env: {})
|
||||
@directives = Default.new(base_url: base_url, env: env).directives
|
||||
@base_url = base_url
|
||||
end
|
||||
|
||||
|
||||
Reference in New Issue
Block a user