CSP Nonces and strict-dynamic Shift Script Trust to Authorized Roots
Content Security Policy can restrict script execution without maintaining a long list of trusted hostnames. A nonce-based policy gives selected script elements an unpredictable, response-specific token. When strict-dynamic is also present, a supporting browser can propagate trust from those authorized root scripts to scripts they create programmatically. This changes the security boundary. Trust is attached to an authorized execution root rather than every network origin that might serve JavaScript. A nonce authorizes a specific script element A server can emit a policy such as: