我在Cordova 5.4.1中使用以下插件:
index.html标头包含此CSP元标记(必须对google TalkBack网址进行uglify):
<meta http-equiv="Content-Security-Policy"
content="default-src 'self' 'unsafe-inline' 'unsafe-eval'
data: gap: content: cdvfile: ....google-URLS...;
img-src data: gap: file: content: cdvfile: ....google-URLS...;
style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval';
connect-src 'self' ....google-URLS..." />
config.xml包括:
<allow-navigation href="http://*/*" />
<access origin="*://*" />
<allow-intent href="content://*" />
<allow-intent href="content://*/*/*/*" />
我的画布相关代码看起来像这样并且工作正常,当画布显示带有file:/// * URL的图像,而不是像内容这样的URLS:/// *
html2canvas($("#layerA"), {onrendered:function(stageCanvas){
var stageCtx = stageCanvas.getContext('2d');
var tmpCanvas = document.createElement('canvas');
tmpCanvas.width = stageCanvas.width;
tmpCanvas.height = stageCanvas.height;
var tmpCtx = stageCanvas.getContext('2d');
var imgObj = new Image();
imgObj.onload = function(){
var destX = 0;
var destY = 0;
tmpCtx.drawImage(imgObj,
sourceX, sourceY, sourceWidth, sourceHeight,
0, 0, destWidth, destHeight);
var data = tmpCtx.getImageData(sourceX, sourceY, sourceWidth, sourceHeight);
stageCtx.clearRect(0, 0, stageCanvas.width, stageCanvas.height); //clear originalCanvas
stageCanvas.width = sourceWidth;
stageCanvas.height = sourceHeight;
tmpCtx.putImageData(data,0,0);
var datauri = null;
try {
datauri = stageCanvas.toDataURL('image/png');
} catch(err) {
alert(err);
}
// store the image and update UI
$('#fav-img-'+maxFavUsed.toString()).attr('src', datauri);
$("#fav-del-"+maxFavUsed.toString()).show();
$('#fav-big').attr('src', datauri);
if(typeof(Storage) !== "undefined") {
localStorage.setItem('fav-img-'+maxFavUsed.toString(), datauri);
}
showFav(maxFavUsed);
showUI();
//clear memory!!!
stageCtx.clearRect(0, 0, sourceWidth, sourceHeight);//clear originalCanvas
tmpCtx.clearRect(0, 0, sourceWidth, sourceHeight);//clear tmpCanvas
data = null;
datauri = null;
tmpCanvas = null;
stageCanvas = null;
imgObj = null;
};
try {
imgObj.src = tmpCanvas.toDataURL("image/png");
} catch(err) {
alert(err);
}
}, width:canvasW, height:canvasH } );
上面的代码不会抛出并且不会发出警报但会创建空的数据库,所以我认为画布受到了CORS问题的污染。以content://开头的URL由XAPKReader插件附带的java类ContentProvider提供。
答案 0 :(得分:0)
我自己找到了一条路。看起来Android上的画布绘图并不关心CSP元条目和白名单插件。因此,在调用上述代码之前,我使用XMLHttpRequest()
和.readAsDataURL()
来替换 background-image 网址中的图像引用。因此,我还必须将我的ContentProvider权限content://FOO:*
添加到CSP元标记的 connect-src:部分。然后画布正确渲染。