Conversation
supportI’m trying to disable script-src nonce and use unsafe-inline, but I am still getting nonces in the header. Here’s what I did: I set External source csp mode: to none. I turned on Use ‘ unsafe-hashes ‘ for JS event handlers attributes of HTML elements. (Say NO). We have a lot of base rules we setup.
Please, read: https://github.com/MocioF/No-unsafe-inline/issues/3
Thank you, that worked.
Please, read: https://github.com/MocioF/No-unsafe-inline/issues/3
Thank you, that worked.