【发布时间】:2012-08-12 14:42:18
【问题描述】:
如何修改John Resig's microtemplating 引擎使其不使用new Func or eval。我想要相同的行为但没有new Func:
/ Simple JavaScript Templating
// John Resig - http://ejohn.org/ - MIT Licensed
(function () {
var cache = {};
this.tmpl = function tmpl(str, data) {
// Figure out if we're getting a template, or if we need to
// load the template - and be sure to cache the result.
var fn = !/\W/.test(str) ?
cache[str] = cache[str] ||
tmpl(document.getElementById(str).innerHTML) :
// Generate a reusable function that will serve as a template
// generator (and which will be cached).
new Function("obj",
"var p=[],print=function(){p.push.apply(p,arguments);};" +
// Introduce the data as local variables using with(){}
"with(obj){p.push('" +
// Convert the template into pure JavaScript
str
.replace(/[\r\t\n]/g, " ")
.split("<%").join("\t")
.replace(/((^|%>)[^\t]*)'/g, "$1\r")
.replace(/\t=(.*?)%>/g, "',$1,'")
.split("\t").join("');")
.split("%>").join("p.push('")
.split("\r").join("\\'")
+ "');}return p.join('');");
// Provide some basic currying to the user
return data ? fn(data) : fn;
};
})();
【问题讨论】:
-
而你为什么要这样做?你害怕脚本注入吗?
-
因为 chrome 扩展不允许我这样做(新的乐趣)。它给了我“未捕获的错误:此上下文不允许从字符串生成代码”stackoverflow.com/questions/11968234/…
标签: javascript jquery templates jquery-templates