discourse/lib/content_security_policy
David Taylor ee08a8c52b
Revert "FIX: Omit CSP nonce and hash values when unsafe-inline enabled (#25590)" (#25609)
This reverts commit 767b49232e.

If anything else (e.g. GTM integration) introduces a nonce/hash, then this change stops the splash screen JS to fail and makes sites unusable.
2024-02-08 11:44:09 +00:00
..
builder.rb Revert "FIX: Omit CSP nonce and hash values when unsafe-inline enabled (#25590)" (#25609) 2024-02-08 11:44:09 +00:00
default.rb FIX: Avoid flash-of-unstyled-content in Safari with bug workaround (#25462) 2024-01-29 17:20:44 +00:00
extension.rb DEV: Make csp cache work like other caches (#20818) 2023-03-27 09:22:38 -05:00
middleware.rb SECURITY: Don't reuse CSP nonce between anonymous requests 2023-07-28 12:53:44 +01:00