Stott Security 2.3 #178
GeekInTheNorth
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Version 2.3.0
This update has been published to api.nuget.optimizely.com and nuget.org.
This release introduces support for for
nonceandstrict-dynamicfor thescript-src,style-srcand their derivatives. Please note that there is some specific extra steps for ensuring your script and style tags have theirnonceattributes updated, so checkout the Read Me. There has been some interesting challenges in making the CSPnoncework for the site and as such I've had to conditionally apply it depending on whether you are on a content page or within the CMS editor experience.If you'd like to support a change for
noncesupport in the CMS Editor / Administrator experience, then please visit this page and vote for this change: Support CSP with nonce in Edit, Admin etcFeatures
strict-dynamicin the CSP.Nonceandstrict-dynamicwill be applied only to content pages and the header listing API.This discussion was created from the release Stott Security 2.3.0.0.
Help me celebrate this release with a coffee! ☕️
All reactions