Skip to main content

NONCE

Constant NONCE 

Source
pub const NONCE: &str = "'nonce'";
Expand description

Placeholder for the request’s nonce: sent as 'nonce-<value>' (Rails’ content_security_policy_nonce).

Put it in script_src or style_src; the layer generates a new random nonce per request and handlers get it with the CspNonce extractor, to write <script nonce="{{ nonce }}">.

§Examples

use ocre::security::{ContentSecurityPolicy, NONCE, SELF};

let csp = ContentSecurityPolicy::new().script_src(&[SELF, NONCE]);
assert_eq!(csp.header_value(Some("abc")), "script-src 'self' 'nonce-abc'");