<script>
accept integrity
attribute, so I can load a module safely:
<script type="module"
src="https://example.com/module.mjs"
integrity="sha256-2Kok7MbOyxpgUVvAk/HJ2jigOSYS2auK4Pfzbm7uH60="
crossorigin="anonymous"
></script>
But how to keep safe when loading module inside script?
- with import:
import foo from "https://example.com/module.mjs"
- dynamic import:
import("https://example.com/module.mjs").then(console.log)
- or even web worker:
const myWorker = new Worker('worker.js')