Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

174
Vistas
CSP with javascript in "document.location"

Our application is being updated to comply with new CSP (Content Security Policy) rules.

E.g. Inline event handlers are replaced with addEventListener(), and inline styles replaced with CSS.

However, in some instances document location is set to a javascript expression, like so...

document.location = 'javascript:someFunction()';

...which causes the following error...

"Refused to run the JavaScript URL because it violates the following Content Security Policy directive: "script-src 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 

My question: What is an equivalent way of re-writing this so that it complies with CSP rules?

about 4 years ago · Juan Pablo Isaza
1 Respuestas
Responde la pregunta

0

It is blocked by unsafe-inline. Please consider either:

  1. If someFunction() returns an valid URI, you can write document.location = someFunction(); as @ControlAltDel mentions.
  2. If it does not, you can just call someFunction().
about 4 years ago · Juan Pablo Isaza Denunciar
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda