Skip to content
This repository was archived by the owner on Nov 24, 2022. It is now read-only.
This repository was archived by the owner on Nov 24, 2022. It is now read-only.

idea: check for nonce #12

@rvaneijk

Description

@rvaneijk

Hi,

The current report on SRI does not check for nonce, but flags non-SRI if no hash is implemented.

For example, <script 'nonce-d3gxy7nm8y4yjr' src="https://d3gxy7nm8y4yjr.cloudfront.net/js/embed.js" type="text/javascript"></script> is flagged as 'Subresource Integrity (SRI) not implemented,'

I ran the report on the URI https://www.natuurlijkehaarkleuring.nl/afspraak/

Proposed resulution: check for nonce-script tags when running the SRI reporter.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions