New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix: CSP with unsafe-eval detection with Trusted Types #27446
Conversation
unsafe-eval
detection with Trusted Types2deeff3
to
a49aa51
Compare
a49aa51
to
ec8334b
Compare
9971606
to
1c22dba
Compare
1c22dba
to
6d8bcaf
Compare
Release Notes Persisted
|
I was unable to backport this PR to "12-x-y" cleanly; |
I was unable to backport this PR to "9-x-y" cleanly; |
I have automatically backported this PR to "10-x-y", please check out #27468 |
I have automatically backported this PR to "11-x-y", please check out #27469 |
Description of Change
Fixes #27211
Need to use
eval('')
instead ofnew Function('')
due to a bug in Trusted Types for function constructor.Before:
After:
Checklist
npm test
passesRelease Notes
Notes: Fixed CSP with
unsafe-eval
detection with Trusted Types.