no-script-url
Disallow javascript: URLs
Using javascript: URLs is considered by some as a form of eval. Code passed in javascript: URLs has to be parsed and evaluated by the browser in the same way that eval is processed.
Rule Details
Examples of incorrect code for this rule:
Open in Playground
/*eslint no-script-url: "error"*/
location.href = ;
location.href = ;
Compatibility
- JSHint: This rule corresponds to
scripturlrule of JSHint.
Version
This rule was introduced in ESLint v0.0.9.