fix: remove nonce from style-src to allow unsafe-inline to work
CI / check (push) Successful in 29s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m11s

This commit is contained in:
openhands committed 2026-08-01 22:09:22 +02:00
1 parent 95b1955218
commit c7fb37356e
2 files changed
+1 -3

No files matched your search

+1 -2
View File
@@ -13,8 +13,7 @@ describe("csp", () => {
expect(csp).toContain("script-src");
expect(csp).toContain("'nonce-testNonce123'");
expect(csp).not.toMatch(/script-src[^;]*'unsafe-inline'/);
expect(csp).toContain("style-src 'self' 'nonce-testNonce123'");
expect(csp).not.toMatch(/style-src(?!-attr)[^;]*'unsafe-inline'/);
expect(csp).toContain("style-src 'self' 'unsafe-inline'");
expect(csp).toContain("style-src-attr 'unsafe-inline'");
expect(csp).toContain("https://challenges.cloudflare.com");
expect(csp).toContain("https://cdn.jsdelivr.net");
-1
View File
@@ -19,7 +19,6 @@ export function buildContentSecurityPolicy(nonce: string): string {
const styleSrc = [
"'self'",
"'unsafe-inline'",
`'nonce-${nonce}'`,
"https://fonts.googleapis.com",
].join(" ");