Business
Jobs
  • About Us
  • Solutions
    • Job Postings
      Post your job and receive qualified candidates in 48h.
    • Candidate Assessments
      500+ technical and psychological tests, plus anti-fraud.
    • Headhunting
      Tailor-made executive search from start to finish.
    • Payroll + EOR
      Payroll dispersal and EOR across 15+ LATAM countries.
  • Pricing
  • Jobs

0

166
Views
CSP with javascript in "document.location"

Our application is being updated to comply with new CSP (Content Security Policy) rules.

E.g. Inline event handlers are replaced with addEventListener(), and inline styles replaced with CSS.

However, in some instances document location is set to a javascript expression, like so...

document.location = 'javascript:someFunction()';

...which causes the following error...

"Refused to run the JavaScript URL because it violates the following Content Security Policy directive: "script-src 'unsafe-eval' 'strict-dynamic' 'unsafe-inline' 

My question: What is an equivalent way of re-writing this so that it complies with CSP rules?

about 4 years ago · Juan Pablo Isaza
1 answers
Answer question

0

It is blocked by unsafe-inline. Please consider either:

  1. If someFunction() returns an valid URI, you can write document.location = someFunction(); as @ControlAltDel mentions.
  2. If it does not, you can just call someFunction().
about 4 years ago · Juan Pablo Isaza Report
Answer question
Find remote jobs

Discover the new way to find a job!

Top jobs
Top job categories
Business
Post vacancy Pricing Sales
Legal
Terms and conditions Privacy policy
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Show me some job opportunities
There's an error!