Snippet
2Add a CSP nonce to inline scripts
Generate a per-request nonce so you can drop 'unsafe-inline' from your Content-Security-Policy.
BC
Ben Carter
Government Digital Service · 26 Sept 2026
function mytheme_page_attachments_alter(array &$attachments) {
$nonce = \Drupal::service('csp.nonce')->getValue();
$attachments['#attached']['drupalSettings']['cspNonce'] = $nonce;
}
Join GDDN to upvote and share your own resources.
