Your achievements

Level 1

0% to

Level 2

Tip /
Sign in

Sign in to Community

to gain points, level up, and earn exciting badges like the new
BedrockMission!

Learn more

View all

Sign in to view all badges

CSP Nonce for different subdomains

TomaszPiekutows
Level 1
Level 1

Hello,

in my comapny we track few subdomains using one Launch property.

 

Because of Content Security Policy we need to implement "nonce" only on one subdomain and only on that domain server will generate nonce value. In Core extension we can set CSP Nonce for whole property. I can set data element to get nonce value only when this value exists, however I'm wondering if this will cause any problems on subdomains where nonce is not defined. I tried to test it and it seems that i.e. AA tracking seems to be ok, but I'm not sure if it can cause any other problems.

 

On subdomain where nonce will be genrated we will use async deployment.

On subdoamins where nonce will not be generated we will use sync deployment.

 

Maybe you have some tips how to manage it? Thanks

 

0 Replies