tl;dr CSP Lv.2ã®nonceã使ãã¨æå¤ã¨ç°¡åã«CSPã®æ©æµãåãããã Firefoxã¯unsafe-inlineã¨ã®æåãããããã®ã§æ³¨æ ãµã³ãã«å®è£ ã¨ãã¦Expressã§ç°¡åã«nonce対å¿ã§ããconnectãã©ã°ã¤ã³ãæ¸ããï¼ãã¢ããï¼ Violation Reportããã©ã¦ã¶ã«ãã£ã¦ç´°ããæåã®å·®ç°ãããã CSP Lv.2 nonceã®ç»å ´ã¨èæ¯ CSPã®ç¹ã«unsafe-inlineã¯XSSã«å¯¾ãã¦æçµé²è¡ç·çã«å¼·åãªå¹æãããã ãããç¹ã«ãµã¼ãã¼ããã®å¤ã®åã渡ãé¨åãªã©ã§ã©ããã¦ãinline scriptã使ããããªãã¨ããããããunsafe-inlineãç¦æ¢ããã¨DOM dataçã使ããããå¾ããã¤ããæãã ã£ãã @kazuho ã§ããããã¨ãã£ã¦DOM dataãã¼ããã¨ããæãã§ã¯ãããã§ãããCSPã§inline scriptç¦æ¢ãã¡
{{#tags}}- {{label}}
{{/tags}}