Hello all. I am working to make our webapp compliant with our CSP, and have 
removed `style-src unsafe-inline`. I am working through any errors that 
have popped up, but one is stumping me

At runtime, it appears that GWT is injecting all the CSS from our Ui Binder 
files using StyleInjectorImpl 
<https://www.gwtproject.org/javadoc/latest/com/google/gwt/dom/client/StyleInjector.StyleInjectorImpl.html>
 `injectStyleSheet` 
method. 

This is violating the CSP. Is there any way around this? I'm aware that the 
main way to ensure CSP compliance is to use a nonce value, but due to some 
quirks with our setup, this is not possible. 

-- 
You received this message because you are subscribed to the Google Groups "GWT 
Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/google-web-toolkit/b4c2f50e-7bf9-4947-8000-f9dff600a837n%40googlegroups.com.

Reply via email to