http
HTTP/2 200 OK
Content-Type: text/html
Content-Security-Policy: script-src-elem 'nonce-r@nd0m123' https://cdn.example.com; script-src-attr 'none'
<!DOCTYPE html>
<html>
<head>
<!-- Erlaubt durch Nonce -->
<script nonce="r@nd0m123">
window.APP_CONFIG = {
apiUrl: 'https://api.example.com',
version: '2.1.0'
};
</script>
<!-- Erlaubt durch Source-List -->
<script src="https://cdn.example.com/react.min.js"></script>
<!-- Blockiert (falscher Nonce) -->
<script nonce="wrong">alert('XSS')</script>
<!-- Blockiert durch script-src-attr -->
<button onclick="doSomething()">Click</button>
</head>
</html>