由于安全策略,无法使用Raphael JS在Chrome扩展弹出窗口中绘制路径?

NCh*_*ase 5 javascript svg raphael google-chrome-extension

如果我尝试使用Raphael在我的Chrome扩展程序的default_popup页面中绘制路径:

r.path("M0,0L10,10");
Run Code Online (Sandbox Code Playgroud)

我收到以下错误:

Uncaught EvalError: Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'self' chrome-extension-resource:".
Run Code Online (Sandbox Code Playgroud)

我理解需要禁止eval()和类似的东西,但为什么这会"将字符串作为JavaScript进行评估"?有没有其他方法来生成没有路径字符串的路径,除了设置一个不安全的安全策略,也会结束允许eval()?

Ser*_*gii 17

为了在您的扩展中使用eval(),请在manifest.json中添加以下行(我假设您使用的是清单v2)

"content_security_policy": "script-src 'self' 'unsafe-eval'; object-src 'self'"
Run Code Online (Sandbox Code Playgroud)

正如你可能猜到的那样,指令'unsafe-eval'可以解决问题.


Sud*_*han 0

如果你检查这个简单的例子。

function (params, callback) {
    setTimeout(function () {
        callback(true)
    }, 1000); // CSP
};
Run Code Online (Sandbox Code Playgroud)

上面的代码确实违反了CSP,因为我正在执行定义中的回调函数setTimeout(), setTimeout()收到的是结果callback(true)而不是回调本身。然后需要进行评估,从而触发 Chrome 安全策略。

在类似的行中,我尝试查看Raphel path的源代码,但我的方向不是很好,我假设某些地方必须涉及此类代码。

在chrome扩展中,没有办法超越Eval CSP,我建议使用另一种解决方法或使用纯SVG方法。