Inline handlers on a page with a content policy
- Forbidden
onclick="…"in markup, a<script>with no nonce, on a site that sets a Content-Security-Policy- Instead
- Bind behaviour in script (
E-33asks for a real control anyway), and let the policy's nonce cover the one bootstrap the framework emits.
What this rule looks like
Why this rule
This is where a security decision made in configuration lands on whoever writes the markup: under a strict policy the inline handler simply does not run, and the page fails in the browser rather than in a check.
- Kind
- Rule
- Section
- Things to avoid
- Group
- Safety at the interface
- Bucket
- judgment
- Severity
- note
- Since
- v0.14.0