Description
The current Content-Security-Policy in index.html uses 'unsafe-inline' for both script-src and style-src directives. This weakens XSS protection since inline scripts/styles are allowed.
Suggested implementation
- Generate a nonce at build time via a Vite plugin
- Apply the nonce to the inline script tag and style elements
- Update CSP to use
'nonce-<value>' instead of 'unsafe-inline'
- Alternatively, use
'strict-dynamic' with hash-based CSP for static assets
Benefits
- Stronger XSS protection — blocks injection of unauthorized inline scripts
- Better alignment with security best practices (OWASP CSP recommendations)
- No functional change to the application
Description
The current Content-Security-Policy in
index.htmluses'unsafe-inline'for bothscript-srcandstyle-srcdirectives. This weakens XSS protection since inline scripts/styles are allowed.Suggested implementation
'nonce-<value>'instead of'unsafe-inline''strict-dynamic'with hash-based CSP for static assetsBenefits