Skip to content
Discussion options

You must be logged in to vote

Sorry about that. We've realized that allowing globals defeats the entire purpose of the CSP build and allows people do execute dangerous code in their expressions that gets them around CSP blocks. They can access your nonce and inject their own javascript using globals.

We realize this is surprising and not ideal, but this really is a hard constraint.

We recommend that you extract anything that needs a global into a function or other form of abstraction. Sorry, thanks for understanding.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by simonjnesta
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants