security - How can one implement Google-signin and CSP rejection of inline stylesheets? -


i'm trying enable content-security-policy header on website. have following header set:

content-security-policy:default-src 'self'; script-src 'self' https://apis.google.com/; font-src 'self' https://fonts.gstatic.com/; style-src 'self' https://fonts.googleapis.com/ 'sha256-w/8nelkjrtpkuufkfdnutwiyhlsvdjaxc+do5tqp/90='; child-src 'self' https://accounts.google.com/ 

this works great in firefox. hash in style-src section matches inline styles google-signin uses. problem is, per chromium bug 546106, hash ignored because it's on style, rather script. worse still, comments chrome/chromium developers believe correct behavior, , intended (that said, haven't set "wontfix" yet).

i don't want enable 'unsafe-inline' if don't have to.

is there way google-signin tell not use inline styling? there way?


Comments

Popular posts from this blog

javascript - Confirm a form & display message if form is valid with JQuery -

Retrieving ETA (estimated time of arrival) with Google Distance Matrix API and public transit as transport mode -

ionic framework - Meteor - Error: Failed to execute 'insertBefore' on 'Node' -