Skip to content

fix: preserve CSP values during nonce substitution - #106

Open
bensynapse wants to merge 1 commit into
unrolled:v1from
bensynapse:fix-csp-nonce-substitution
Open

bensynapse wants to merge 1 commit into
unrolled:v1from
bensynapse:fix-csp-nonce-substitution

Conversation

@bensynapse

Copy link
Copy Markdown

I run Live Tennis API.

Using $NONCE in one policy currently sends both CSP policy strings through fmt.Sprintf. A static companion policy receives %!(EXTRA string=...). Percent encoded URLs inside nonce policies also become formatting diagnostics.

Substitute the $NONCE markers directly. Both headers keep their other text, and the handler still receives a fresh nonce for each request.

make ci passes on Go 1.21.13 and 1.26.0, including race tests and vet. The configured golangci-lint 2.12.2 check passes. All seven new regression cases fail on unchanged v1 and pass with the fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant