问题
Javascript doesn't seem to be working in my cordova app, and I don't seem to be able to figure out what I'm doing wrong here. I know for sure in a normal webbrowser the html and javascript works fine.
Below is my code, I'm creating a simple calculator.
index.html:
<!DOCTYPE html>
<!--
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
-->
<html>
<head>
<!--
Customize this policy to fit your own app's needs. For more guidance, see:
https://github.com/apache/cordova-plugin-whitelist/blob/master/README.md#content-security-policy
Some notes:
* gap: is required only on iOS (when using UIWebView) and is needed for JS->native communication
* https://ssl.gstatic.com is required only on Android and is needed for TalkBack to function properly
* Disables use of inline scripts in order to mitigate risk of XSS vulnerabilities. To change this:
* Enable inline JS: add 'unsafe-inline' to default-src
-->
<meta http-equiv="Content-Security-Policy" content="default-src 'self' data: gap: https://ssl.gstatic.com 'unsafe-eval'; style-src 'self' 'unsafe-inline'; media-src *; img-src 'self' data: content:;">
<meta name="format-detection" content="telephone=no">
<meta name="msapplication-tap-highlight" content="no">
<meta name="viewport" content="user-scalable=no, initial-scale=1, maximum-scale=1, minimum-scale=1, width=device-width">
<link rel="stylesheet" type="text/css" href="css/design.css">
<title>Calculator</title>
</head>
<body>
<div id="calculator">
<form>
<input type="text" id="display" disabled><br>
<input type="button" value="C" id="keys" onclick="addtoscreen('c')">
<input type="button" value="<--" id="keys" onclick="backspace()">
<input type="button" value="X^2" id="keys" onclick="power(2)">
<input type="button" value="+" id="keys" onclick="addtoscreen('+')"><br>
<input type="button" value="9" id="keys" onclick="addtoscreen('9')">
<input type="button" value="8" id="keys" onclick="addtoscreen('8')">
<input type="button" value="7" id="keys" onclick="addtoscreen('7')">
<input type="button" value="-" id="keys" onclick="addtoscreen('-')"><br>
<input type="button" value="6" id="keys" onclick="addtoscreen('6')">
<input type="button" value="5" id="keys" onclick="addtoscreen('5')">
<input type="button" value="4" id="keys" onclick="addtoscreen('4')">
<input type="button" value="*" id="keys" onclick="addtoscreen('*')"><br>
<input type="button" value="3" id="keys" onclick="addtoscreen('3')">
<input type="button" value="2" id="keys" onclick="addtoscreen('2')">
<input type="button" value="1" id="keys" onclick="addtoscreen('1')">
<input type="button" value="/" id="keys" onclick="addtoscreen('/')"><br>
<input type="button" value="0" id="keys" onclick="addtoscreen('0')">
<input type="button" value="." id="keys" onclick="addtoscreen('.')">
<input type="button" value="=" id="equal" onclick="answer()">
</form>
</div>
</body>
<script type="text/javascript" src="js/logic.js"> </script>
</html>
logic.js:
var box = document.getElementById("display");
function addtoscreen(x){
box.value +=x;
if(x == "c"){
box.value='';
}
}
function answer(){
x=box.value
x=eval(x);
box.value=x;
}
function backspace(){
var number=box.value;
var len= number.length-1;
var newnumber=number.substring(0, len)
box.value=newnumber;
}
function power(y){
x=box.value;
x=Math.pow(x, y);
box.value=x;
}
回答1:
I believe the problem is in your Content-Security-Policy meta tag. You are preventing inline script. The following code should work.
<meta http-equiv="Content-Security-Policy" content="default-src 'unsafe-inline' data: gap: https://ssl.gstatic.com; style-src 'self' 'unsafe-inline'; media-src *">
There is more information about the Content-Security-Policy on your own file ;) https://github.com/apache/cordova-plugin-whitelist/blob/master/README.md#content-security-policy
回答2:
For other people having the same problem, I fixed it by adding this line.
<meta http-equiv="Content-Security-Policy" content="default-src *; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' 'unsafe-eval'">
more information can be found here: https://cordova.apache.org/docs/en/latest/reference/cordova-plugin-whitelist/
来源:https://stackoverflow.com/questions/42936228/javascript-not-working-in-cordova-app