/ live.thehmm.nl / back / node_modules / get-nonce /

[ICO]NameLast modifiedSizeDescription
[PARENTDIR]Parent Directory  -  
[DIR]dist/2 years ago -  
[TXT]CHANGELOG.md40 years ago 21  
[   ]LICENSE40 years ago1.0K 
[TXT]README.md40 years ago1.5Kd7c1522 post receive test [كارل مبارك]
[   ]package.json2 years ago2.6K 
README.md

get-nonce

just returns a nonce (number used once). No batteries included in those 46 bytes of this library.


API

Why?

Why we need a library to access __webpack_nonce__? Abstractions!

"I", as a library author, don't want to "predict" the platform "you" going to use. "I", as well, want an easier way to test and control nonce value.

Like - nonce is supported out of the box only by webpack, what you are going to do?

This is why this "man-in-the-middle" was created. Yep, think about left-pad :)

Webpack

https://webpack.js.org/guides/csp/

To activate the feature set a webpack_nonce variable needs to be included in your entry script.

__webpack_nonce__ = uuid(); // for example

Without webpack __webpack_nonce__ is actually just a global variable, which makes it actually bundler independent, however "other bundlers" are able to replicate it only setting it as a global variable (as here in tests) which violates a "secure" nature of nonce.

get-nonce is not global.

Used in

Inspiration

Licence

MIT

Apache/2.4.38 (Debian) Server at www.karls.computer Port 80