fix: pass nonce to importmap script when using subResourceIntegrity#14675
Conversation
When unstable_subResourceIntegrity is enabled, the importmap script tag was missing the nonce attribute, causing CSP violations when strict Content Security Policy is enforced without 'unsafe-inline'. This fix ensures the nonce attribute is properly passed to the importmap script element, allowing applications to use strict CSP policies. Fixes remix-run#14252
🦋 Changeset detectedLatest commit: a28ae1a The changes in this PR will be included in the next version bump. This PR includes changesets to release 11 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
Hi @dimmageiras, Welcome, and thank you for contributing to React Router! Before we consider your pull request, we ask that you sign our Contributor License Agreement (CLA). We require this only once. You may review the CLA and sign it by adding your name to contributors.yml. Once the CLA is signed, the If you have already signed the CLA and received this response in error, or if you have any questions, please contact us at [email protected]. Thanks! - The Remix team |
|
Thank you for signing the Contributor License Agreement. Let's get this merged! 🥳 |
|
Thanks! Can you add a changeset file to the branch via |
cbcf4b7 to
7888e17
Compare
I hope I did it properly |
|
🤖 Hello there, We just published version Thanks! |
|
🤖 Hello there, We just published version Thanks! |
Description
When
unstable_subResourceIntegrityis enabled, the importmap script tag was missing thenonceattribute, causing CSP violations when strict Content Security Policy is enforced without'unsafe-inline'.This fix ensures the
nonceattribute is properly passed to the importmap script element, allowing applications to use strict CSP policies.Changes
nonce={scriptProps.nonce}to the importmap script elementImpact
unsafe-inlineFixes #14252