mirror of
https://github.com/jquery/jquery.git
synced 2024-10-05 11:34:18 +00:00
4250b62878
Stringifying attributes in the setter was needed for IE <=9 but it breaks trusted types enforcement when setting a script `src` attribute. Note that this doesn't mean script execution works. Since jQuery disables all scripts by changing their type and then executes them by creating fresh script tags with proper `src` & possibly other attributes, this unwraps any trusted `src` wrappers, making the script not execute under strict CSP settings. We might try to fix it in the future in a separate change. Fixes gh-4948 Closes gh-4949
2 lines
35 B
JavaScript
2 lines
35 B
JavaScript
window.testMessage = "script run";
|