Split inline scripts from an HTML file for CSP compliance
Command line usage:
cat index.html | crisper -h build.html -j build.js
crisper --source index.html --html build.html --js build.js
crisper --html build.html --js build.js index.html
The output html file will load the output js file at the top of <head>
with a <script defer>
element.
Optional Flags:
--script-in-head=false
<body>
document.write
support.--only-split
<script>
tag in the output HTML
file.--always-write-script
<script>
elements.--csp-hashable-script-loader
script-src 'strict-dynamic' 'sha256-mUZwR5zj1qMvnzisSvfmC8JczLB0BUKW0Ohr3euDoIA=';
object-src 'none';
base-uri 'self';
-v
| --version
Library usage:
var output = crisper({
source: 'source HTML string',
jsFileName: 'output js file name.js',
scriptInHead: true, //default true
onlySplit: false, // default false
alwaysWriteScript: false // default false
});
fs.writeFile(htmlOutputFileName, output.html, 'utf-8', ...);
fs.writeFile(jsOutputFileName, output.js, 'utf-8', ...);
When using vulcanize, crisper can handle the html string output directly and write the CSP separated files on the command line
vulcanize index.html --inline-script | crisper --html build.html --js build.js
Or programmatically
vulcanize.process('index.html', function(err, cb) {
if (err) {
return cb(err);
} else {
var out = crisper({
source: html,
jsFileName: 'name of js file.js',
scriptInHead: true, // default true
onlySplit: false, // default false
alwaysWriteScript: false //default false
})
cb(null, out.html, out.js);
}
});
split
API was removed
require('crisper').split()
script-in-head
flag changed to true
document.write
calls--script-in-head=false
argument or
scriptInHead: false
in library usage.