4 ms·
I'd love to use HTMX at work. Sadly the security folks would probably balk at checking in JS code that uses eval(), even though you can disable eval at runtime
by kweingar 2y ago
I'd love to use HTMX at work. Sadly the security folks would probably balk at checking in JS code that uses eval(), even though you can disable eval at runtime in the HTMX config.
I thought about writing a script to remove all references to eval (and all tests relying on eval), but at that point it would probably be easier to just rewrite the library.
- recursivedoubts 2y agoeval can be disabled at the CSP level, which is much better than at the source level (which can always be obfuscated, missed in a version update, etc)
- viraptor 2y agoIt can be, but then you discover how marketing added lots of gtag and other content which is already full of eval ;)
- recursivedoubts 2y agooof