Skip to content
GitHub
Sections

Reference · Things to avoid

Inline handlers on a page with a content policy

Forbidden
onclick="…" in markup, a <script> with no nonce, on a site that sets a Content-Security-Policy
Instead
Bind behaviour in script (E-33 asks for a real control anyway), and let the policy's nonce cover the one bootstrap the framework emits.

What this rule looks like

Forbidden
Instead

Why this rule

This is where a security decision made in configuration lands on whoever writes the markup: under a strict policy the inline handler simply does not run, and the page fails in the browser rather than in a check.

Kind
Rule
Section
Things to avoid
Group
Safety at the interface
Bucket
judgment
Severity
note
Since
v0.14.0

Read as plain text