Content Security Policy CSP And Nonce - Question | JoomShaper
Black Friday sale is live with flat 50% OFF. Sale ends soon! Grab your deal now!

Content Security Policy CSP And Nonce

MR

marius van Rijnsoever

SP Page Builder 2 years ago

Hi

CSP is now the expected security standard to prevent XSS attacks.

https://blog.astrid-guenther.de/en/cassiopeia/10content-security-policy-joomla4/

Would it be possible for page builder pro to check if httpheaders has nonce enabled and put this code into the <style type="text/css"> tag

It works for javascript as this gets added using the joomla API, but not for the inline CSS.

Thanks, Marius

0
1 Answers
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 years ago #139226

Hi there,

I appreciate you reaching out. I sincerely apologize for this oversight. I need to share your issue to our developer team. I will get back to you soon.

-Thanks

0