I am working on implementing Nonce for a setup that has an Apache 2.4.43 server and utilises HTML, CSS and JavaScript.
Since we would like to have a server-side implementation, I am using Apache module mod_unique_id to generate a unique key. However the generated key is not base64-encoded (https://httpd.apache.org/docs/2.4/mod/mod_unique_id.html). Trying to manipulate the generated key and encoding it using base64 in .conf file like this does not seem to work:
RequestHeader set %{UNIQUE_ID}e "expr=%{base64:%{reqenv:UNIQUE_ID}e}"
The generated nonce still has unacceptable characters sometimes. Any ideas and suggestions on what more is required here?
Also, the generated nonce has to be added to the "script" tags loading the JavaScript code and the "link" tags loading the stylesheets (not sure if link tags allow nonce attributes) in index.html.
An example of how to effectively have this done from within .conf would be very helpful.
UPDATE:
I could not find a way to base64 encode the Apache-generated key in httpd.conf. Finally ended up modifying the source code of the Apache module.
However, I am still looking for a way to insert nonce into script tags in index.html that is loading external scripts and stylesheets.