Content Security Policy allow inline style without unsafe-inline

∥☆過路亽.° 提交于 2019-12-05 16:26:24

According to https://bugzilla.mozilla.org/show_bug.cgi?id=855326#c35 nonces for style attributes isn't supported

a common workaround for this issue is to write the inline-style (or inline-script) data to an input tag:

<input id="my-font-size" type="hidden" value="16" />

or in HTML5:

<input id="my-id" data-font-size="16" />

and process the data via an external included JavaScript (to avoid violating "script-src" csp):

$('span').css('font-size', $('#my-id').data('font-size'));
易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!