From cb2b7ce5d607081f1bb75dcf123086b20b18ae4e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C3=89tienne=20Barri=C3=A9?= Date: Thu, 25 May 2023 12:10:18 +0200 Subject: [PATCH] Don't generate a nonce The need for a nonce was removed in 3ba21de59b76b60335988eff2b08db0c51d542d6 --- app/controllers/maintenance_tasks/application_controller.rb | 5 ----- 1 file changed, 5 deletions(-) diff --git a/app/controllers/maintenance_tasks/application_controller.rb b/app/controllers/maintenance_tasks/application_controller.rb index 9205b689..78bc707b 100644 --- a/app/controllers/maintenance_tasks/application_controller.rb +++ b/app/controllers/maintenance_tasks/application_controller.rb @@ -20,11 +20,6 @@ class ApplicationController < MaintenanceTasks.parent_controller.constantize policy.frame_ancestors(:self) end - before_action do - request.content_security_policy_nonce_generator ||= ->(_request) { SecureRandom.base64(16) } - request.content_security_policy_nonce_directives = ["style-src"] - end - protect_from_forgery with: :exception end end