TrustedScriptURL: toString() method

Limited availability

This feature is not Baseline because it does not work in some of the most widely-used browsers.

The toString() method of the TrustedScriptURL interface returns a string which may safely inserted into an injection sink.

Syntax

js
toString()

Parameters

None.

Return value

A string containing the sanitized URL

Examples

The constant sanitized is an object created via a Trusted Types policy. The toString() method returns a string to safely use to load a third party script.

js
const sanitized = scriptPolicy.createScriptURL(
  "https://example.com/my-script.js",
);
console.log(sanitized.toString());

Specifications

Specification
Trusted Types
# trustedscripturl-stringification-behavior

Browser compatibility

BCD tables only load in the browser