Bug 273185

Summary: Block eval with strings when trusted types enforced
Product: WebKit Reporter: Luke Warlow <lwarlow>
Component: JavaScriptCoreAssignee: Luke Warlow <lwarlow>
Status: RESOLVED FIXED    
Severity: Normal CC: webkit-bug-importer
Priority: P2 Keywords: InRadar
Version: Safari 17   
Hardware: Unspecified   
OS: Unspecified   
See Also: https://github.com/web-platform-tests/wpt/pull/46484
Bug Depends on:    
Bug Blocks: 267694    

Luke Warlow
Reported 2024-04-24 06:38:10 PDT
When trusted types are enforced string arguments to eval should not be executed unless the default policy exists and allows it.
Attachments
Luke Warlow
Comment 1 2024-04-29 05:53:19 PDT
Radar WebKit Bug Importer
Comment 2 2024-05-01 06:39:15 PDT
EWS
Comment 3 2024-05-29 16:50:38 PDT
Committed 279473@main (7a4725b0e729): <https://commits.webkit.org/279473@main> Reviewed commits have been landed. Closing PR #27868 and removing active labels.
Note You need to log in before you can comment on or make changes to this bug.