Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy

Viewed 741

I'm getting this error whenever a link to my website's Twitter page is clicked in the footer of my webpage the link is included inline HTML which I guess the Content Security Policy doesn't like?

I see I can simply add 'unsafe-eval' to the policy but that may create a higher chance that my website/app is exposed to XSS. This happened while running open testing on an android app in google play it's specific to the Android 8 device which has an older SDK(26) then the other devices tested that didn't have any issues my app has a target SDK 30 could this cause an issue for that device? anyway here's the error message and the footer

hasMessage: true message: Refused to evaluate a string as JavaScript because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'self'
 <footer>
            <div class='social'><a href='https://www.instagram.com/mypage/'><i class='icon ion-social-instagram'></i></a><a href='https://twitter.com/mypage'><i class='icon ion-social-twitter'></i></a><a href='https://www.facebook.com/mypage'><i class='icon ion-social-facebook'></i></a></div>
            <ul class='list-inline' >
                <li class='list-inline-item'><a href='about.html'>About</a></li>
                <li class='list-inline-item'><a href='terms.html'>Terms and Conditions</a></li>
                <li class='list-inline-item'><a href='privacy.html'>Privacy Policy</a></li>
                                <li class="list-inline-item"><a href="contactus.php">Contact Us</a></li>
            </ul>
            <p class='copyright'>MySite © 2021</p>
</footer>

I'd just like to clarify how to go about addressing this error since I've never seen this error before and I'm relatively fresh to deploying android apps and would like to publish my app now.

0 Answers
Related