We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 3290224 commit 9dcedaaCopy full SHA for 9dcedaa
variants/backend-base/config/initializers/content_security_policy.rb
@@ -124,7 +124,7 @@
124
# ###############
125
126
# If you are using UJS then enable automatic nonce generation
127
- config.content_security_policy_nonce_generator = ->(_request) { SecureRandom.base64(16) }
+ config.content_security_policy_nonce_generator = ->(request) { request.session.id.to_s }
128
129
# Set the nonce only to specific directives
130
# config.content_security_policy_nonce_directives = %w(script-src)
0 commit comments