AngularJS ng-cspDirective
AngularJS Example
Modify AngularJS's behavior regarding "eval" and inline styles:
...
Try it yourself »
Definition and Usage
ng-cspThe directive is used to modify AngularJS's security policy.
If using theng-cspdirective, AngularJS will not execute the eval function, making it impossible to inject inline styles.
Setng-cspdirective tono-unsafe-eval, this will prevent AngularJS from executing the eval function, but allow injecting inline styles.
Setng-cspdirective to no-inline-style, this will prevent AngularJS from injecting inline styles, but allow executing the eval function.
If developing Google Chrome extensions or Windows appsng-cspthe directive is required.
Note:ng-cspThe directive does not affect JavaScript, but it modifies the way AngularJS works. This means: you can still write eval functions, and they can execute normally, but AngularJS cannot execute its own eval function. If compatibility mode is adopted, performance will be reduced by 30%.
Syntax
Parameter Values
| Value | Description |
|---|---|
| no-unsafe-eval no-inline-style |
The value can be set to empty, meaning neither eval nor inline styles are allowed. You can set one of the values. You can also set both values separated by a semicolon, but this has the same effect as leaving it empty. |
Other Extensions
AngularJS Reference Manual