W3C home > Mailing lists > Public > public-webappsec@w3.org > July 2012

Secure dynamic JS compilation under CSP

From: John J Barton <johnjbarton@johnjbarton.com>
Date: Thu, 19 Jul 2012 10:45:37 -0700
Message-ID: <CAFAtnWzmBThywOEg+M5_iN1h-_EOf5NsGrhNoKZGCTr29HU2og@mail.gmail.com>
To: public-webappsec@w3.org
Hi. I was looking into converting my application to use CSP when I learned
that neither eval nor new Function() are allowed. I have a large
application that uses these features to compile JS at runtime. I am
wondering what alternatives are available.

Received on Thursday, 19 July 2012 17:46:04 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 18:54:28 UTC