- Issue created by @OmManiPadmeHum
- 🇨🇦Canada gapple
There's some discussion of strict-dynamic in ✨ Allow script / style by nonce Postponed .
Since the ability to use strict-dynamic is dependent on the libraries a site uses, and previously even Drupal Core itself was incompatible, there hasn't been work to integrate it as a feature in the module.
There was also originally the issue of browser support for strict-dynamic, but I don't think that's still a concern with all modern browsers now supporting CSP 3.I think core support, csp modules features, and browser support have all progressed enough that restoring strict-dynamic as a configurable option on the module is feasible now, but it will need some thought for implementation given that the target user for the config form is site builders. The effect of using it needs to be clear, reporting of violations visible, and easily reversible.
- 🇫🇷France OmManiPadmeHum
Thanks for the answer.
May be we can close this issue as duplicate of issue ✨ Allow script / style by nonce Postponed to continue in it. - 🇨🇦Canada gapple
I'll postpone this issue as a separate item to enable 'strict-dynamic' after making it possible to use a nonce for library scripts.