You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Sep 25, 2021. It is now read-only.
Repository navigation
This repository was archived by the owner on Sep 25, 2021. It is now read-only.
For any production use, my recommendation is to make use of compiled templates.
Using those compiled template functions only requires a minimal runtime that does not make use of new Function or any other unsafe-eval construct.
It is the result of following the tutorial/documentation you have provided. I followed the guide step by step and installed the template like:
npm install blueimp-tmpl -g
But may be this is an issue on node. I'm using the latest version on windows. Can you provide a concrete example of how to use the tmpl.js compiler in the wiki?
Sorry I don't provide support to run this on Windows.
If you're on Windows 10, I recommend you to run it inside of Windows Subsystem for Linux.
However if you want to figure out how to make this work under Windows and would like to write a guide with step-by-step instructions, I'd gladly add a link to the Wiki.
The
new Function(...), user here: https://github.com/blueimp/JavaScript-Templates/blob/master/js/tmpl.js#L24is a bad practice, and disabled by default if using Content Security Policy (see here)
Can this be replaced? Otherwise who uses CSP must add
unsafe-evalto use this library, allowing potential secutiry vulnerabilities.