> For the complete documentation index, see [llms.txt](https://mavolin.gitbook.io/corgi/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mavolin.gitbook.io/corgi/learning-corgi/nonce-injection.md).

# Nonce Injection

Corgi can automatically inject `nonce` attributes into `script` elements to be used with a Content Security Policy.

To enable nonce injection, simply place a compiler directive above the func header, with a Go expression retrieving the nonce:

```pug
import "context"

//corgi:nonce ctx.Value("nonce")
func Foo(ctx context.Context)

script
  > let foo = "bar"
```

<pre class="language-go"><code class="lang-go">nonce := make([]byte, 16)
if _, err := rand.Read(nonce); err != nil {
    panic(err)
}

<strong>nonceB64 := base64.StdEncoding.ToString(nonce)
</strong>
ctx := context.WithValue(context.Background(), "nonce", nonceB64)
Foo(ctx)
</code></pre>

```markup
<script nonce="8IBTHwOdqNKAWeKl7plt8g==">
  let foo = "bar"
</script>
```
