CSP compliance

18 views
Skip to first unread message

Amaury Bouchard

unread,
Dec 16, 2015, 7:10:56 AM12/16/15
to jSmart - JavaScript template engine with Smarty syntax
Hi,

Thanks for the work done on the jSmart library :)

It seems that it is not CSP compliant. I saw some eval() in the code.
This compliance is required on some platforms like Google Chrome Apps, in order to access the full API (otherwise, the application is stuck in a sandbox).


Is there a CSP-compliant version planned in the future?

Regards,

Amaury Bouchard

Max Miroshnikov

unread,
Dec 16, 2015, 7:54:10 AM12/16/15
to jSmart - JavaScript template engine with Smarty syntax
Hi,

thanks for using jsmart,

I wasn't comfortable with using eval() when I wrote the library, but I tended to see it as necessary evil.
Now, since it places limitations on the library usage, we should find a way to get rid of eval()s.
So there will definitely be a version without them.
Reply all
Reply to author
Forward
0 new messages