1
0 Comments

PayPal SDK and CSP doesn't play well; So what are you doing?

If you are using Content Security Policy (which everyone should), PayPal says to send nonce only that it's not doing what needs to be done in its back end and so the nonce isn't propagated to the style-src resulting in styles are not being set.

The issue is open for over a year now, So I wonder what others are doing? Not using CSP or making it weak by allowing inline scripts or Not using PayPal SDK at all?

on December 28, 2020