From 4096d8d6bd69944880f96ef5205ec872da336277 Mon Sep 17 00:00:00 2001 From: maziggy Date: Sat, 23 May 2026 12:28:58 +0200 Subject: [PATCH] fix(csp): nonce-based script-src so Cloudflare-injected scripts pass (#1460 follow-up) Behind Cloudflare, the bot-detection script CF injects into every HTML response carries a hash that rotates per request, so it can never be allowlisted by hash. Reporters with CF in front had to relax their NPM CSP to 'unsafe-inline' as a workaround. Per Cloudflare's documented behaviour, when a nonce is present in the page's script-src, CF clones it onto its injected