eval
usage is not allowed when using a sensible CSP #106
Closed
Description
I recently added a content security policy to my site and now I'm seeing this error:
nextZero EvalError: Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'self' blob:".
. It's because this library is using an eval
call here:
I'm wondering if this can be rewritten to use a different parsing strategy. Using
eval
is generally discouraged.Metadata
Assignees
Labels
No labels