Skip to content

Commit f666e44

Browse files
committed
Avoid tying CSP {nonce} placeholder to specific stacks
Signed-off-by: Ziqin Wang <ziqin@wangziqin.net>
1 parent 939ae10 commit f666e44

2 files changed

Lines changed: 2 additions & 2 deletions

File tree

web/src/main/java/org/springframework/security/web/header/writers/ContentSecurityPolicyHeaderWriter.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -120,7 +120,7 @@ public final class ContentSecurityPolicyHeaderWriter implements HeaderWriter {
120120

121121
private static final String DEFAULT_SRC_SELF_POLICY = "default-src 'self'";
122122

123-
public static final String NONCE_PLACEHOLDER = "{nonce}";
123+
private static final String NONCE_PLACEHOLDER = "{nonce}";
124124

125125
private String policyDirectives;
126126

web/src/main/java/org/springframework/security/web/server/header/ContentSecurityPolicyServerHttpHeadersWriter.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ public final class ContentSecurityPolicyServerHttpHeadersWriter implements Serve
6161

6262
public static final String CONTENT_SECURITY_POLICY_REPORT_ONLY = "Content-Security-Policy-Report-Only";
6363

64-
public static final String NONCE_PLACEHOLDER = "{nonce}";
64+
private static final String NONCE_PLACEHOLDER = "{nonce}";
6565

6666
private @Nullable String policyDirectives;
6767

0 commit comments

Comments
 (0)