TrustedScript: toString() method

Limited availability

This feature is not Baseline because it does not work in some of the most widely-used browsers.

The toString() method of the TrustedScript interface returns a string which may safely inserted into an injection sink.

Syntax

js
toString()

Parameters

None.

Return value

A string containing the sanitized script.

Examples

The constant sanitized is an object created via a Trusted Types policy. The toString() method returns a string to safely execute as a script.

js
const sanitized = scriptPolicy.createScript("eval('2 + 2')");
console.log(sanitized.toString());

Specifications

Specification
Trusted Types
# trustedscripturl-stringification-behavior

Browser compatibility

BCD tables only load in the browser