Defer scriptEval test until first use to prevent Content Security Policy inline-script violations from occuring. Fixes #7371.
This commit is contained in:
parent
f01ef93aab
commit
220a0ce162
|
@ -583,7 +583,7 @@ jQuery.extend({
|
||||||
|
|
||||||
script.type = "text/javascript";
|
script.type = "text/javascript";
|
||||||
|
|
||||||
if ( jQuery.support.scriptEval ) {
|
if ( jQuery.support.scriptEval() ) {
|
||||||
script.appendChild( document.createTextNode( data ) );
|
script.appendChild( document.createTextNode( data ) );
|
||||||
} else {
|
} else {
|
||||||
script.text = data;
|
script.text = data;
|
||||||
|
|
|
@ -4,10 +4,7 @@
|
||||||
|
|
||||||
jQuery.support = {};
|
jQuery.support = {};
|
||||||
|
|
||||||
var root = document.documentElement,
|
var div = document.createElement("div");
|
||||||
script = document.createElement("script"),
|
|
||||||
div = document.createElement("div"),
|
|
||||||
id = "script" + jQuery.now();
|
|
||||||
|
|
||||||
div.style.display = "none";
|
div.style.display = "none";
|
||||||
div.innerHTML = " <link/><table></table><a href='/a' style='color:red;float:left;opacity:.55;'>a</a><input type='checkbox'/>";
|
div.innerHTML = " <link/><table></table><a href='/a' style='color:red;float:left;opacity:.55;'>a</a><input type='checkbox'/>";
|
||||||
|
@ -64,7 +61,7 @@
|
||||||
deleteExpando: true,
|
deleteExpando: true,
|
||||||
optDisabled: false,
|
optDisabled: false,
|
||||||
checkClone: false,
|
checkClone: false,
|
||||||
scriptEval: false,
|
_scriptEval: null,
|
||||||
noCloneEvent: true,
|
noCloneEvent: true,
|
||||||
boxModel: null,
|
boxModel: null,
|
||||||
inlineBlockNeedsLayout: false,
|
inlineBlockNeedsLayout: false,
|
||||||
|
@ -77,6 +74,12 @@
|
||||||
select.disabled = true;
|
select.disabled = true;
|
||||||
jQuery.support.optDisabled = !opt.disabled;
|
jQuery.support.optDisabled = !opt.disabled;
|
||||||
|
|
||||||
|
jQuery.support.scriptEval = function() {
|
||||||
|
if ( jQuery.support._scriptEval === null) {
|
||||||
|
var root = document.documentElement,
|
||||||
|
script = document.createElement("script"),
|
||||||
|
id = "script" + jQuery.now();
|
||||||
|
|
||||||
script.type = "text/javascript";
|
script.type = "text/javascript";
|
||||||
try {
|
try {
|
||||||
script.appendChild( document.createTextNode( "window." + id + "=1;" ) );
|
script.appendChild( document.createTextNode( "window." + id + "=1;" ) );
|
||||||
|
@ -88,21 +91,28 @@
|
||||||
// tag with appendChild/createTextNode
|
// tag with appendChild/createTextNode
|
||||||
// (IE doesn't support this, fails, and uses .text instead)
|
// (IE doesn't support this, fails, and uses .text instead)
|
||||||
if ( window[ id ] ) {
|
if ( window[ id ] ) {
|
||||||
jQuery.support.scriptEval = true;
|
jQuery.support._scriptEval = true;
|
||||||
delete window[ id ];
|
delete window[ id ];
|
||||||
|
} else {
|
||||||
|
jQuery.support._scriptEval = false;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
root.removeChild( script );
|
||||||
|
// release memory in IE
|
||||||
|
root = script = id = null;
|
||||||
|
}
|
||||||
|
return jQuery.support._scriptEval;
|
||||||
|
};
|
||||||
|
|
||||||
// Test to see if it's possible to delete an expando from an element
|
// Test to see if it's possible to delete an expando from an element
|
||||||
// Fails in Internet Explorer
|
// Fails in Internet Explorer
|
||||||
try {
|
try {
|
||||||
delete script.test;
|
delete div.test;
|
||||||
|
|
||||||
} catch(e) {
|
} catch(e) {
|
||||||
jQuery.support.deleteExpando = false;
|
jQuery.support.deleteExpando = false;
|
||||||
}
|
}
|
||||||
|
|
||||||
root.removeChild( script );
|
|
||||||
|
|
||||||
if ( div.attachEvent && div.fireEvent ) {
|
if ( div.attachEvent && div.fireEvent ) {
|
||||||
div.attachEvent("onclick", function click() {
|
div.attachEvent("onclick", function click() {
|
||||||
// Cloning a node shouldn't copy over any
|
// Cloning a node shouldn't copy over any
|
||||||
|
@ -191,6 +201,6 @@
|
||||||
jQuery.support.changeBubbles = eventSupported("change");
|
jQuery.support.changeBubbles = eventSupported("change");
|
||||||
|
|
||||||
// release memory in IE
|
// release memory in IE
|
||||||
root = script = div = all = a = null;
|
div = all = a = null;
|
||||||
})();
|
})();
|
||||||
})( jQuery );
|
})( jQuery );
|
||||||
|
|
Loading…
Reference in a new issue