[wp-trac] [WordPress Trac] #53902: Automating the creation of inline javascript and inline stylesheet nonces or hashes

WordPress Trac noreply at wordpress.org
Sun Jun 30 17:21:24 UTC 2024


#53902: Automating the creation of inline javascript and inline stylesheet nonces
or hashes
--------------------------------+------------------------------
 Reporter:  Josiah S. Carberry  |       Owner:  (none)
     Type:  feature request     |      Status:  new
 Priority:  normal              |   Milestone:  Awaiting Review
Component:  Security            |     Version:
 Severity:  normal              |  Resolution:
 Keywords:                      |     Focuses:  javascript
--------------------------------+------------------------------

Comment (by jornfranke):

 Is there an update on this? It is good that unsafe-eval is not needed
 anymore with the latest Gutenberg version. However, unsafe-inline seems to
 be still an open issue.

 Is there a ticket where one can track the progress of unsafe-inline and
 see what is still outstanding?

 It would be good if it can be resolved as the security and privacy of the
 WordPress users can be much better protected (given also the many
 vulnerability of third party plugins).

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/53902#comment:4>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list