启用CSP后加载WASM的问题及结论
问题
近期在HTTP头中启用了Content Security Policy(CSP),但使用的某依赖库需要动态加载并编译WASM。若不在CSP的script-src中添加unsafe-eval,WASM模块无法实例化,报错信息如下:
CompileError: WebAssembly.instantiate(): Refused to compile or instantiate WebAssembly module because 'unsafe-eval' is not an allowed source of script in the following Content Security Policy directive: "script-src 'self' https://cdn.jsdelivr.net blob: 'nonce-maskedValue'
已尝试以下无效方案:
- 在
script-src中添加unsafe-wasm-eval无效 - 自行托管WASM并内部加载无效
- 结合Subresource Integrity(SRI)与
strict-dynamic无效
寻求可行的解决思路或方向。
已确认的结论与解决方案
我们得出结论:WASM本身确实需要unsafe-eval。目前该指令已加入CSP,除非满足以下条件:
- WASM不使用
eval()、Function等动态代码执行方法。相关规则可参考W3C CSP3规范中script-src指令的第4、5点。
内容的提问来源于stack exchange,提问作者Tommy Leong
相关产品推荐
相关产品推荐

