diff --git a/sections/advanced/security.mdx b/sections/advanced/security.mdx index bd102f03..ded72859 100644 --- a/sections/advanced/security.mdx +++ b/sections/advanced/security.mdx @@ -21,3 +21,55 @@ Be very careful! This is obviously a made-up example, but CSS injection can be u have bad repercussions. You can use [`CSS.escape`](https://developer.mozilla.org/en-US/docs/Web/API/CSS/escape) to sanitize CSS from JavaScript. It is well-supported in all modern browsers. + +### Content Security Policy | v6.4+ + +If your app uses a [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) that restricts inline styles, you need to provide a nonce so the browser allows styled-components' injected `