Nonce Generator
This module generates a unique nonce for each request, which can be automatically added to Content Security Policy headers. Developers can then create plugins to output scripts that automatically use these nonces, preventing CSP violations even with cached content.
Generates fresh CSP nonces per request and automatically injects them into script-src Content Security Policy headers.
What It Does
This module generates a unique nonce for each HTTP request and automatically adds it to your CSP headers. The module itself doesn't add any scripts — you create plugins to output scripts that use the nonce.
How it works
- ✅ Scripts get fresh nonces on every request via lazy builders
- ✅ No CSP violations even with cached content
Creating a Plugin
Create a plugin class in your module at src/Plugin/NonceScript/MyScript.php:
<?php
namespace Drupal\mymodule\Plugin\NonceScript;
use Drupal\nonce_generator\Plugin\NonceScript\NonceScriptPluginBase;
/**
* @NonceScript(
* id = "my_script",
* label = @Translation("My Script")
* )
*/
class MyScript extends NonceScriptPluginBase {
public function getScript(string $nonce): string {
$escaped_nonce = htmlspecialchars($nonce, ENT_QUOTES, 'UTF-8');
return <<<SCRIPT
<script type="text/javascript" nonce="{$escaped_nonce}">
console.log("Hello from my script!");
// Add more JavaScript here
</script>
SCRIPT;
}
}
Adding to Templates
Use in render arrays or templates:
// Render a specific plugin
$build['my_script'] = [
'#type' => 'nonce_script',
'#plugin_id' => 'my_script',
];
// Render all active plugins
$build['all_scripts'] = [
'#type' => 'nonce_script',
'#all_plugins' => TRUE,
];
Depends on
Dependencies of the latest stable release
No dependencies recorded for this project.
Required by
1 tracked project depends on this one
- Nonce Piwik Plugin 3 sites
Activity
Release Timeline
Releases
| Version | Type | Core | Notes | Release date | |
|---|---|---|---|---|---|
| 1.0.0 | Stable | 10–11 | Version 1.0.0 – first stable release | Aug 6, 2026 | |
| 1.0.0-beta6 | Pre-release | 10–11 | Apr 14, 2026 | ||
| 1.0.0-beta5 | Pre-release | 10–11 | Making sure nonces are not added when there is an unsafe-inline present | Sep 5, 2025 | |
| 1.0.0-beta4 | Pre-release | 10–11 | Improved configuration form language for better clarity and security awareness. | Sep 2, 2025 | |
| 1.0.0-beta3 | Pre-release | 10–11 | Sep 2, 2025 | ||
| 1.0.0-beta2 | Pre-release | 10–11 | Code improvements + new nonce every request for anonymous users | Aug 16, 2025 | |
| 1.0.0-beta1 | Pre-release | 10–11 | Initial beta release | Aug 12, 2025 | |
| 1.x-dev | Dev | 10–11 | initial dev release | Aug 12, 2025 |