Closed
Nonce Tag Usage
When Implementing CSP Headers across the application, how is the Nonce Tag referenced and used?
This content is closed to future replies and is no longer being maintained or updated.
Links may no longer function. If you have a similar request, please write a new post.
When Implementing CSP Headers across the application, how is the Nonce Tag referenced and used?
@MarvinW1 can you confirm that you are referring to this documentation What's new in security 8.7
@MarijeSchillern so when i try to implement the Nonce tag it is not found as an option of the CSP Rule. How do we turn it on?
Thanks,
Marvin
The version I am running is 8.7.3
did you follow the steps as detailed in external documentation?
https://content-security-policy.com/nonce/
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/script-src
https://developer.mozilla.org/en-US/docs/Web/HTML/Global_attributes/nonce
Do you believe this to be a Pega issue?
Can you provide screenshots illustrating how you are configuring the nonce value and a time stamp to the Script-Src directive in the Content Security Policy?
Question
Question
Question
Discussion
Question
Question
Question
Question
Question
Discussion
Pega Collaboration Center has detected you are using a browser which may prevent you from experiencing the site as intended. To improve your experience, please update your browser.