TrustedScript interface of the
Trusted Types API represents a string with an uncompiled script body that a developer can insert into an injection sink that might execute the script. These objects are created via
TrustedTypePolicy.createScript() and therefore have no constructor.
sanitized is an object created via a Trusted Types policy.
const sanitized = scriptPolicy.createScript("eval('2 + 2')"); console.log(sanitized); /* a TrustedScript object */
|Trusted Types |
BCD tables only load in the browser