gpt4 book ai didi

javascript - 从 Textarea 执行 Javascript - JSHint eval 是邪恶的

转载 作者:行者123 更新时间:2023-11-30 12:17:05 26 4
gpt4 key购买 nike

fiddle - http://jsbin.com/zepugadafa/edit?js,output

我最近了解到 Eval .

我的脚本工作正常,但 JSHint 说 eval is evil

我不想禁用来自 Codemirror 的评估警报。只需重写我的点击函数(仍然使用 eval 或其他形式的 eval 使其以完全相同的方式工作)。

我试过...

$("#download").on("click", function() {
var call = new Function( $("#jszipdemo").val() );
return call();
});

但是得到了Function constructor is a form of eval.


我发现没有任何错误的唯一方法是将脚本附加到主体,但仍然没有想出替代措施,我认为这并不是多余的,因为我喜欢分离我的 javascript来 self 的 html 的代码。

var script = "<script>" + content + "</script>";
$('body').append(script);

有谁知道摆脱此警报的解决方法,同时仍然运行我的函数(无需在 Codemirror 上禁用 eval,并且不必将脚本附加到正文中)?

var widgets = [];
var waiting;

function updateHints() {
editor.operation(function(){
for (var i = 0; i < widgets.length; ++i)
editor.removeLineWidget(widgets[i]);
widgets.length = 0;

JSHINT(editor.getValue());
for (i = 0; i < JSHINT.errors.length; ++i) {
var err = JSHINT.errors[i];
if (!err) continue;
var msg = document.createElement("div");
var icon = msg.appendChild(document.createElement("span"));
icon.innerHTML = "!!";
icon.className = "lint-error-icon";
msg.appendChild(document.createTextNode(err.reason));
msg.className = "lint-error";
widgets.push(editor.addLineWidget(err.line - 1, msg, {coverGutter: false, noHScroll: true}));
}
});
var info = editor.getScrollInfo();
var after = editor.charCoords({line: editor.getCursor().line + 1, ch: 0}, "local").top;
if (info.top + info.clientHeight < after)
editor.scrollTo(null, after - info.clientHeight + 3);
}

editor = CodeMirror.fromTextArea(document.getElementById("jszipdemo"), {
lineNumbers: true,
mode: "javascript",
lint: true,
gutters: ["CodeMirror-lint-markers"]
});

editor.on("change", function() {
clearTimeout(waiting);
waiting = setTimeout(updateHints, 500);
});

setTimeout(updateHints, 100);
@import url("http://necolas.github.io/normalize.css/3.0.1/normalize.css");
@import url("http://codemirror.net/lib/codemirror.css");
@import url("http://codemirror.net/addon/fold/foldgutter.css");
@import url("https://codemirror.net/addon/lint/lint.css");


.CodeMirror {
float: left;
width: 100%;
}
.lint-error {
font-family: arial;
font-size: 70%;
background: #ffa;
color: #a00;
padding: 2px 5px 3px;
}
.lint-error-icon {
color: white;
background-color: red;
font-weight: bold;
border-radius: 50%;
padding: 0 3px;
margin-right: 7px;
}
<script src="https://ajax.googleapis.com/ajax/libs/jquery/2.1.1/jquery.min.js"></script>
<script src="http://codemirror.net/lib/codemirror.js"></script>
<script src="http://codemirror.net/javascripts/code-completion.js"></script>
<script src="http://codemirror.net/javascripts/css-completion.js"></script>
<script src="http://codemirror.net/javascripts/html-completion.js"></script>
<script src="http://codemirror.net/mode/javascript/javascript.js"></script>
<script src="http://codemirror.net/mode/xml/xml.js"></script>
<script src="http://codemirror.net/mode/css/css.js"></script>
<script src="http://codemirror.net/mode/htmlmixed/htmlmixed.js"></script>
<script src="http://codemirror.net/addon/edit/closetag.js"></script>
<script src="http://codemirror.net/addon/edit/matchbrackets.js"></script>
<script src="http://codemirror.net/addon/selection/active-line.js"></script>
<script src="http://codemirror.net/keymap/extra.js"></script>
<script src="http://codemirror.net/addon/fold/foldcode.js"></script>
<script src="http://codemirror.net/addon/fold/foldgutter.js"></script>
<script src="http://codemirror.net/addon/fold/brace-fold.js"></script>
<script src="http://codemirror.net/addon/fold/xml-fold.js"></script>
<script src="http://codemirror.net/addon/fold/comment-fold.js"></script>
<script src="https://codemirror.net/addon/lint/lint.js"></script>
<script src="https://ajax.aspnetcdn.com/ajax/jshint/r07/jshint.js"></script>
<script src="https://codemirror.net/addon/lint/javascript-lint.js"></script>

<script src="http://stuk.github.io/jszip/dist/jszip.min.js"></script>
<script src="http://stuk.github.io/jszip-utils/dist/jszip-utils.js"></script>
<script src="http://stuk.github.io/jszip/vendor/FileSaver.js"></script>

<textarea id="jszipdemo" rows="4" cols="35">$("#download").on("click", function() {
return eval( $("#jszipdemo").val() );
});</textarea>

最佳答案

调用 JSHint 并将 evil 选项设置为 false。

JSHINT(editor.getValue(), {evil:false});

关于javascript - 从 Textarea 执行 Javascript - JSHint eval 是邪恶的,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/32159428/

26 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com