DEV Community

Discussion on: Using Google Tag Manager with a Content-Security-Policy

Collapse
 
kraxi profile image
Kraxi

The whole purpose of using nonces with the CSP is to generate a nonce PER RESPONSE not per client. What is the best approach to update the nonce variable on the GTM side in the proper configuration?

Collapse
 
matijamrkaic profile image
Matija Mrkaic

The approach in this article will always give a unique nonce, i.e. refreshing the page generates a new nonce.