Get CSP nonce working with Rails javascript_packs_with_chunks_tag

Viewed 554

I am using Rails 5.2 with webpacker 4 and recently switched to using splitChunks. My web pages now reference my web pack using the javascript_packs_with_chunks_tag.

Now that I want to start using CSP (Content Security Policy) with the SecureHeaders gem I am coming across CSP errors:

homepage-5879edcf6f8ba98035c2.chunk.js:2 
[Report Only] Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'self' 'nonce-dlcwKLQTKthCJgmDqEWu1SX05nIjRY/9r+6ixP5CP4A=' 'unsafe-inline'".

I know SecureHeaders gem have a nonce helper method for normal javascript tags: nonced_javascript_include_tag.

Does anyone know how to add nonce to the javascript_packs_with_chunks_tag to eliminate this error?

0 Answers
Related