[
https://issues.apache.org/jira/browse/WICKET-7092?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17803023#comment-17803023
]
Martin Tzvetanov Grigorov commented on WICKET-7092:
---------------------------------------------------
But I agree that [https://www.w3.org/TR/CSP3/#framework-directive-source-list]
is the leading spec here and all is fine !
So, I am OK to close this ticket as "Won't fix"
> Content Security Policy 'Nonces should only use the base64 charset'
> -------------------------------------------------------------------
>
> Key: WICKET-7092
> URL: https://issues.apache.org/jira/browse/WICKET-7092
> Project: Wicket
> Issue Type: Bug
> Components: wicket-core
> Affects Versions: 9.16.0
> Environment: Kali Linux
> Reporter: sundar
> Priority: Minor
> Attachments: image-20240103-092246.png
>
>
> Hi all, I applied a strict content security policy to my application using
> wicket after I tested my application using Kali Linux to check for
> vulnerabilities. The tool provides the report with an info message "Nonces
> should only use the base64 charset" regarding the info message needed to
> configure any properties in CSP. I attached the report screenshotÂ
--
This message was sent by Atlassian Jira
(v8.20.10#820010)