Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(CSP): allow nonce #97

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Conversation

arahansen
Copy link

@arahansen arahansen commented Dec 14, 2017

adding functionality for a nonce attribute to be applied to the injected style tag. This allows stricter CSP security settings to be applied server side, while still allowing for style injection.

This follows a convention set by webpack as seen here (it's essentially undocumented functionality).

And follows a similar setup to how styled components implements nonce attributes.

I tried to keep the bundle size under 1KB, but opted to bump up the threshold in favor of retaining readability of the file. If keeping it to 1KB is important, I can look for other savings? or maybe start uglifying this file to be a more representative format of what most consumers will ingest this lib as.

@codecov-io
Copy link

Codecov Report

Merging #97 into master will not change coverage.
The diff coverage is 100%.

Impacted file tree graph

@@          Coverage Diff          @@
##           master    #97   +/-   ##
=====================================
  Coverage     100%   100%           
=====================================
  Files           4      4           
  Lines         107    109    +2     
=====================================
+ Hits          107    109    +2
Impacted Files Coverage Δ
src/monolithic.js 100% <100%> (ø) ⬆️

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 61e40b2...bd2ad91. Read the comment docs.

arahansen pushed a commit to gymnastjs/gymnast that referenced this pull request Dec 15, 2017
Uses a fork of cxs that sets a nonce attribute to the injected style tag if it is globally available. Related cxs PR to merge this functionality into the base lib: cxs-css/cxs#97
arahansen pushed a commit to gymnastjs/gymnast that referenced this pull request Dec 15, 2017
Uses a fork of cxs that sets a nonce attribute to the injected style tag if it is globally available. Related cxs PR to merge this functionality into the base lib: cxs-css/cxs#97
arahansen added a commit to gymnastjs/gymnast that referenced this pull request Dec 15, 2017
Uses a fork of cxs that sets a nonce attribute to the injected style tag if it is globally available. Related cxs PR to merge this functionality into the base lib: cxs-css/cxs#97
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants