Skip to content

Comment on Hardening the Firefox Front End with Content Security Policiesparent

Comments

It does seem like CSP nonces do not play well with caching (since they must have a different value on each page load), which would make them a detriment to performance.

You can also include a hash of the contents in the CSP, which plays well with caching.

True, a hash works as a good alternative. (Unless you're doing super weird stuff like generating inline scripts at runtime.)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.