To use nonce csp should include script-src: self, style-src: self

This commit is contained in:
hiromi-mi 2020-06-20 08:51:09 +09:00
parent 51a424aa15
commit 58a14c4ab0

5
app.py
View file

@ -100,14 +100,15 @@ csrf.init_app(app)
csp = {
"default-src": "'self'",
"script-src": "'self'",
"style-src-attr": "'unsafe-inline'",
"script-src": "'self'", # to use nonce
"style-src": "'self'", # to use nonce
}
talisman = Talisman(
app,
content_security_policy=csp,
force_https=False,
force_https=False, # internal requests like /tasks/* are sent over HTTP
content_security_policy_nonce_in=["script-src", "style-src"],
)