我试图在单独的JS脚本中使用事件侦听器使按钮执行某些操作。
我在浏览器中收到此错误(指向<body onload="onLoad()">
行):
Refused to execute inline event handler because it violates the following Content Security Policy directive...
这是我的HTML:
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Security-Policy" content="default-src 'self' data: gap: https://ssl.gstatic.com 'unsafe-eval'; style-src 'self' 'unsafe-inline'; media-src *; img-src 'self' data: content:;">
<meta name="format-detection" content="telephone=no">
<meta name="msapplication-tap-highlight" content="no">
<meta name="viewport" content="user-scalable=no, initial-scale=1, maximum-scale=1, minimum-scale=1, width=device-width">
<link rel="stylesheet" type="text/css" href="css/index.css">
<title>Test</title>
<script type="text/javascript" src="cordova.js"></script>
<script type="text/javascript" src="js/index.js"></script>
</head>
<body onload="onLoad()">
<div id="left_panel">
<div class="btn" id="add" onclick="insert()">Add</div>
</div>
<div id="list">
</div>
</body>
</html>
JS脚本:
function onLoad() {
document.addEventListener("deviceready", onDeviceReady, false);
}
function onDeviceReady() {
document.addEventListener("pause", onPause, false);
document.addEventListener("resume", onResume, false);
document.addEventListener("menubutton", onMenuKeyDown, false);
document.getElementById("list").addEventListener("insert", insert, false);
}
function insert() {
...
}
function onPause() {}
function onResume() {}
function onMenuKeyDown() {}
答案 0 :(得分:0)
尝试:
添加到config .xml中:
<access origin="*" />
<allow-intent href="http://*/*" />
<allow-intent href="https://*/*" />
<platform name="android">
<allow-intent href="market:*" />
</platform>
以及在index.html中:
<meta http-equiv="Content-Security-Policy" content="default-src *; style-src * 'unsafe-inline'; script-src * 'unsafe-inline' 'unsafe-eval'; img-src * data: 'unsafe-inline'; connect-src * 'unsafe-inline'; frame-src *;">
<meta http-equiv="Content-Security-Policy" content="default-src * gap://ready file:; style-src 'self' 'unsafe-inline' *; script-src 'self' 'unsafe-inline' 'unsafe-eval' *">
答案 1 :(得分:0)
该消息表明您的错误在HTML文档的第三行中。有您的内容安全政策,请仔细阅读错误,然后使用正确的参数添加'script-src'以激活javascript的执行:
script-src 'self' 'unsafe-inline' 'unsafe-eval'