Angular’s recommended CSP doesn’t make sense to me
I am trying to implement a CSP policy for our Angular 18 application based on Angular’s CSP recommendation and I have found that their recommendation does not make sense to me.
Specifically their use of a nonce in their script policy
scrip…