Is Subresource Integrity any useful for inline JavaScript?

Viewed 1971

I'm reading about Subresource Integrity and understand it's meant for verifying external files. I guess it's no surprise I couldn't find any reference to inline JavaScript from either MDN or W3C.

So, is it safe to say that the SRI-related attributes, integrity and crossorigin, are completely useless for inline JavaScript ?

4 Answers

If you are looking for protecting inline script files you can use the nonce attribute in CSP headers and specify that on the script tag

nonce-base64-value
A whitelist for specific inline scripts using a cryptographic nonce (number used once). The server must generate a unique nonce value each time it transmits a policy. It is critical to provide an unguessable nonce, as bypassing a resource’s policy is otherwise trivial. See unsafe inline script for an example. Specifying nonce makes a modern browser ignore 'unsafe-inline' which could still be set for older browsers without nonce support.

I know that the thread is a little bit older, but the integrity hash check is now supported by the W3C. The script is executed if:

  • the src is set, the integrity attributes is correct AND matches the CSP policy
  • the src is not set, the integrity attribute is correct OR matches the CSP policy

Pull request

WebAppSec Subresource Integrity


EDIT: seems that actually only Chrome support this functionality

Related