Skip to content

CSP: Missing nonce attribute on <style> tags injected by Didomi #106

Description

@plevavas

We’re using a strict Content-Security-Policy with a style-src 'nonce-...' directive.

The <style> tags injected by Didomi (e.g., inside #didomi-host) don’t have a nonce attribute, which causes them to be blocked by the browser.

Would it be possible to add support for setting a nonce?

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions