You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

启用CSP后加载WASM的问题及结论

问题

近期在HTTP头中启用了Content Security Policy(CSP),但使用的某依赖库需要动态加载并编译WASM。若不在CSP的script-src中添加unsafe-eval,WASM模块无法实例化,报错信息如下:

CompileError: WebAssembly.instantiate(): Refused to compile or instantiate WebAssembly module because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'self' https://cdn.jsdelivr.net blob: 'nonce-maskedValue'

已尝试以下无效方案:

  • 在script-src中添加unsafe-wasm-eval无效
  • 自行托管WASM并内部加载无效
  • 结合Subresource Integrity(SRI)与strict-dynamic无效

寻求可行的解决思路或方向。


已确认的结论与解决方案

我们得出结论:WASM本身确实需要unsafe-eval。目前该指令已加入CSP,除非满足以下条件:

  • WASM不使用eval()、Function等动态代码执行方法。相关规则可参考W3C CSP3规范中script-src指令的第4、5点。

内容的提问来源于stack exchange,提问作者Tommy Leong

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 14:12:34