1、Content-Security-Policy
简单示例:
<meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-inline' *.qq.com *.gtimg.com;">
vue中需要加unsafe-eval 属性或者vue采用模板预编译为渲染函数
<meta http-equiv="Content-Security-Policy" content="script-src 'self' 'unsafe-eval' 'unsafe-inline' *.qq.com *.gtimg.com;">
2、Subresource Integrity
简称SRI 子资源完整性,https://developer.mozilla.org/zh-CN/docs/Web/Security/%E5%AD%90%E8%B5%84%E6%BA%90%E5%AE%8C%E6%95%B4%E6%80%A7









网友评论