3 ms·
[disclaimer, I work on the Dart team] While I do believe our Dart/JavaScript interop story will continue to be refined, I do want to point out that the days of
by sethladd 14y ago
[disclaimer, I work on the Dart team]
While I do believe our Dart/JavaScript interop story will continue to be refined, I do want to point out that the days of javascript: URLs and eval are nearly over. The Web is getting a stronger security model through CSP [1] (content security policy). New restrictions put in place by CSP include turning off eval, new Function, inline JavaScript, and more. This is a very good thing, because it reduces the attack vectors for XSS and more.
[1] http://www.html5rocks.com/en/tutorials/security/content-security-policy/ http://www.html5rocks.com/en/tutorials/security/content-secu...