Content-Security-Policy ã® nonce ãå©ç¨ããã¨ãXSS ã®è å¨ãããªã軽æ¸ã§ãã¾ãã ããã§ãWeb Application Framework ã§ã¯ããã©ã«ãã§å¯¾å¿ããã»ããããã®ã§ã¯ãªãããã¨ããæ¨ã @hasegawayosuke ããããæãã¦é ããã®ã§ãå®è£ ã«ã¤ãã¦èãã¦ã¿ã¾ããã ã¨ãããã CSP ã® nonce ã¯ã©ããããã®ãªã®ããèæ ®ããããã«ãã³ã¼ãä¾ãæ¢ãã¦ããã®ã§ãããå®éã«åããµã³ãã«ã¨ãããã®ã nonce é¢é£ã®ãã®ã§è¦å½ããã¾ããã§ããã ããã§ãå®éã«åããµã³ãã«ãç¨æãã¾ããã https://github.com/tokuhirom/csp-nonce-sample 以ä¸ã¯ Sinatra ã§æ¸ããããµã³ãã«ã³ã¼ãã§ãã require 'sinatra' require 'securerandom' get '/' d
{{#tags}}- {{label}}
{{/tags}}