@@ -140,6 +140,13 @@ public function provideRequestAndResponsesForOnKernelResponse()
140140$ this ->createResponse (['Content-Security-Policy ' =>'default-src \'self \' domain.com; script-src \'self \' \'unsafe-inline \'; script-src-elem \'self \'; style-src \'self \' \'unsafe-inline \'; style-src-elem \'self \'' ,'Content-Security-Policy-Report-Only ' =>'default-src \'self \' domain-report-only.com; script-src \'self \' \'unsafe-inline \'; script-src-elem \'self \'; style-src \'self \' \'unsafe-inline \'; style-src-elem \'self \'' ]),
141141 ['Content-Security-Policy ' =>'default-src \'self \' domain.com; script-src \'self \' \'unsafe-inline \'; script-src-elem \'self \' \'unsafe-inline \' \'nonce- ' .$ nonce .'\'; style-src \'self \' \'unsafe-inline \'; style-src-elem \'self \' \'unsafe-inline \' \'nonce- ' .$ nonce .'\'' ,'Content-Security-Policy-Report-Only ' =>'default-src \'self \' domain-report-only.com; script-src \'self \' \'unsafe-inline \'; script-src-elem \'self \' \'unsafe-inline \' \'nonce- ' .$ nonce .'\'; style-src \'self \' \'unsafe-inline \'; style-src-elem \'self \' \'unsafe-inline \' \'nonce- ' .$ nonce .'\'' ,'X-Content-Security-Policy ' =>null ],
142142 ],
143+ [
144+ $ nonce ,
145+ ['csp_script_nonce ' =>$ nonce ,'csp_style_nonce ' =>$ nonce ],
146+ $ this ->createRequest (),
147+ $ this ->createResponse (['Content-Security-Policy ' =>'default-src \'none \'' ,'Content-Security-Policy-Report-Only ' =>'default-src \'none \'' ]),
148+ ['Content-Security-Policy ' =>'default-src \'none \'; script-src \'unsafe-inline \' \'nonce- ' .$ nonce .'\'; style-src \'unsafe-inline \' \'nonce- ' .$ nonce .'\'' ,'Content-Security-Policy-Report-Only ' =>'default-src \'none \'; script-src \'unsafe-inline \' \'nonce- ' .$ nonce .'\'; style-src \'unsafe-inline \' \'nonce- ' .$ nonce .'\'' ,'X-Content-Security-Policy ' =>null ],
149+ ],
143150 [
144151$ nonce ,
145152 ['csp_script_nonce ' =>$ nonce ,'csp_style_nonce ' =>$ nonce ],