• Hi, great plugin!!!
    Based on web.dev “nonces must be regenerated for every page request and they must be unguessable.”,
    But I see the same nonce id for each page on site.
    Can you please add that function?
    Also I see no CSP generated on header. (– generate Content Security Policy header with all nonces and hashes + basics (base-uri ‘self’, google fonts, gravatar, maxcdn.bootstrapcdn…)
    Thanks!

Viewing 1 replies (of 1 total)
  • Thread Starter marknopfler

    (@marknopfler)

    Also I see no CSP generated on header. (– generate Content Security Policy header with all nonces and hashes + basics (base-uri ‘self’, google fonts, gravatar, maxcdn.bootstrapcdn…) OK I see it on “Network” tab in DevTools.

    What about the generation of the nonce for every page?
    Thanks

Viewing 1 replies (of 1 total)

The topic ‘Regeneration for every page’ is closed to new replies.