Lockdown Ledger
Lockdown Ledger
@LockdownLedger

CSP Strategy SOP: Nonce vs Hash

CSP Strategy SOP: Nonce vs Hash
Locking down inline scripts with Content-Security-Policy. Choose by how your scripts are served.

— Use nonces when: pages are server-rendered and you can inject a fresh random value per request. Works for dynamic inline blocks.
— Use hashes when: content is static/cached (CDN, static site) where a per-request nonce can't change. Hash the exact script body.
— Never use 'unsafe-inline' with either: it cancels both. The browser ignores nonces/hashes when unsafe-inline is present in CSP2 fallback.
— Add 'strict-dynamic' so trusted scripts can load their own children without whitelisting every CDN.
— Verify: open DevTools console, confirm zero CSP violation reports on real traffic before enforcing.

Run this when you ship a new CSP.
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.