web api instance method
TrustedTypePolicy: createScript() method
Available in workers
The createScript() method of the TrustedTypePolicy interface creates a TrustedScript object using a policy created by createPolicy().
Syntax
createScript(input)
createScript(input, args)
Parameters
input- : A string containing the string to be sanitized by the policy.
argsOptional- : Additional arguments to be passed to the function represented by
TrustedTypePolicy.
- : Additional arguments to be passed to the function represented by
Return value
A TrustedScript object.
Exceptions
TypeError- : Thrown if
TrustedTypePolicydoes not contain a function to run on the input.
- : Thrown if
Examples
In the below example a string containing a potentially risky script is used as the input for createScript(). The policy can sanitize this script before inserting it into an injection sink that could cause it to be executed.
const sanitized = scriptPolicy.createScript("eval('2 + 2')");
Specifications
SpecificationsStandards references are available on the canonical MDN page.
Browser compatibility
Browser compatibilityCompatibility data is available on the canonical MDN page.