Scriptbar Snippets 🚀
Handy and easy to understand snippets to keep in your browser
test-if-page-allow-adding-inline-javascript.js

#Basic

Run script to test if page allow injecting js or running remote script

This code snippet checks if the page allows creating and executing new inline scripts (script-injection attacks) See https://github.com/bahmutov/disable-inline-javascript-tutorial

For example, Github doesn't allow running remote script. When running this script on github.com, you will see error below

Credit: https://github.com/bahmutov/code-snippets/blob/master/test-script-injection.js

Test to see if page allow running script

/* * This code snippet checks if the page allows creating * and executing new inline scripts (script-injection attacks) * See https://github.com/bahmutov/disable-inline-javascript-tutorial * Credit: https://github.com/bahmutov/code-snippets/blob/master/test-script-injection.js */ (function testInlineScriptInjection() { var el = document.createElement('script'); el.innerText = 'alert("hi there")'; document.body.appendChild(el); // runs the code by default }()); (function testExternalScriptInjection() { var el = document.createElement('script'); el.src = 'https://rawgit.com/hakimel/reveal.js/tree/master/js'; document.body.appendChild(el); }());
Built with ❤️ by @domnguyen and everyone on the internet 🚀