From c332249568c71627275465813a140ab548672ff2 Mon Sep 17 00:00:00 2001 From: Tobias Bengfort Date: Wed, 15 Feb 2023 12:12:49 +0100 Subject: [PATCH] mention downsides of nonces in CSP --- _docs-v6/intro/content-security-policy.md | 12 +++++------- 1 file changed, 5 insertions(+), 7 deletions(-) diff --git a/_docs-v6/intro/content-security-policy.md b/_docs-v6/intro/content-security-policy.md index 4df285fc..125d2263 100644 --- a/_docs-v6/intro/content-security-policy.md +++ b/_docs-v6/intro/content-security-policy.md @@ -18,19 +18,17 @@ FullCalendar's icon-font is embedded into its CSS with a `data:` protcol. You mu ## Dynamically-Generated Styles -FullCalendar injects its own `