Skip to content

ngCspNonce should add the nonce value to the script tags loading the main bundles #27874

Description

@conorblencowe

Which @angular/* package(s) are relevant/related to the feature request?

compiler-cli

Description

ngCspNonce is a great addition and almost solves a lot of the CSP difficulties I'm having but I think is missing some aspects to simplify the process of writing a CSP.

CSP level 3 introduces strict-dynamic for script-src. This avoids needing a whitelist and favours using a nonce (or hash) on scripts. The great part about it is that this "trust" given by a nonce also propagates to scripts that are loaded by the root script. This is particularly important for myself since we load a tracking script which in turn loads a bunch of other tracking services.

This almost works. The problem is that you can't use strict-dynamic in conjunction with 'self'. Angular currently does not add the nonce from ngCspNonce to the runtime/main bundles included at the bottom of the index.html. So, without a nonce or allowing "self" the browser blocks these.

image

Proposed solution

Along with the other inline styles/scripts that ngCspNonce will add the nonce placeholder to, also add this nonce to the bundles.

Alternatives considered

An alternate solution is to avoid strict-dynamic use whitelisting of domains but for an application with more complex scripts it is a lifesaver. Google's CSP evaluator utilises strict-dynamic in their "sample safe policy".

Activity

  1. added this to the needsTriage milestone on Nov 15, 2023
  2. danielritter commented on Nov 16, 2023

    @danielritter

    +1

  3. tomastrajan commented on Nov 20, 2023

    @tomastrajan
    Contributor

    Yes, please!

  4. bschick commented on Jan 28, 2024

    @bschick

    Hard to use strict-dynamic without this

  5. dvero23 commented on Jun 18, 2024

    @dvero23

    Yes please, it would be really helpful.

  6. removed this from the needsTriage milestone on Jun 18, 2024
  7. transferred this issue fromangular/angularon Jun 18, 2024
  8. JoostK commented on Jun 18, 2024

    @JoostK
    Member

    Moving this to the CLI repo because it does the index.html preparation, not the Angular compiler itself.

  9. added a commit that references this issue on Jun 18, 2024
    cc2cef4
  10. added a commit that references this issue on Jun 18, 2024
    bdd168f
  11. added a commit that references this issue on Jun 18, 2024
    c0ceddf
  12. angular-automatic-lock-bot commented on Jul 19, 2024

    @angular-automatic-lock-bot

    This issue has been automatically locked due to inactivity.
    Please file a new issue if you are encountering a similar or related problem.

    Read more about our automatic conversation locking policy.

    This action has been performed automatically by a bot.

  13. locked and limited conversation to collaborators on Jul 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions