AngularJS ng-cspDirective

AngularJS 参考手册AngularJS Reference Manual


AngularJS Example

Modify AngularJS's behavior regarding "eval" and inline styles:

<body ng-app="" ng-csp>
...

Try it yourself »

Definition and Usage

ng-cspThe directive is used to modify AngularJS's security policy.

If using theng-cspdirective, AngularJS will not execute the eval function, making it impossible to inject inline styles.

Setng-cspdirective tono-unsafe-eval, this will prevent AngularJS from executing the eval function, but allow injecting inline styles.

Setng-cspdirective to no-inline-style, this will prevent AngularJS from injecting inline styles, but allow executing the eval function.

If developing Google Chrome extensions or Windows appsng-cspthe directive is required.

Note:ng-cspThe directive does not affect JavaScript, but it modifies the way AngularJS works. This means: you can still write eval functions, and they can execute normally, but AngularJS cannot execute its own eval function. If compatibility mode is adopted, performance will be reduced by 30%.


Syntax

<element ng-csp="no-unsafe-eval | no-inline-style"></element>

Parameter Values

Value Description
no-unsafe-eval
no-inline-style
The value can be set to empty, meaning neither eval nor inline styles are allowed.
You can set one of the values.
You can also set both values separated by a semicolon, but this has the same effect as leaving it empty.

AngularJS 参考手册AngularJS Reference Manual

Other Extensions