CSP: whitelisted javascript with nonce but still get eval error in Chrome

Viewed 657

I am trying to implement a content security policy without unsafe-inline and unsafe-eval in a web application that is asp.net MVC. It has views (cshtml files) with inline javascript. I have moved the javascript code into separate .js files and added a nonce="1234567890" attribute to them. For now, the nonce is static. Once we get things working with the CSP we will implement a dynamic nonce. The issue is I still get evaluation errors in Chrome despite whitelisting with the nonce.

This is the declaration I have in the view:

<script type="text/javascript" src="~/Scripts/NET/Work.js" nonce="1234567890"></script>

This is what's in the js file:

(function() {
    $("button[type='submit']", "#frmWorkOptions").on("click", function () {
        if (_cc._xhrFind)
            _cc._xhrFind.abort();
    });

$(document).ajaxSend(function (event, xhr, options) {
var match;
match = /\/NET\/Work\/Find/i.test(options.url);
if (match)
    _cc._xhrFind = xhr;
});
$("#WorkEditor").focus();

$("#frmWorkOptions").submit();

})();

This is the code being used to call the view (AJAX) and add the content to the page.

route = _cc.getAction("Index", activity);

            var data = { __RequestVerificationToken: token };
            $.post(route, data, function (data, status, xhr) {
                $div.html(data);
            }).fail(function (xhr, status, err) {
                alert("An error occurred processing your request. ");
                window.location = "/";
            });

I am getting an error upon running the page (in Chrome): Refused to execute inline script because it violates the following Content Security Policy directive:... The nonce is correctly in my CSP because I've successfully used it to whitelist other scripts. These scripts loaded with html from the AJAX call seem to be the ones giving me a problem. Any help appreciated.

0 Answers
Related