From a1bb160c700243c1f11a56dc8e92c69afb7db620 Mon Sep 17 00:00:00 2001 From: Martin Artnik Date: Tue, 7 May 2024 14:08:52 +0200 Subject: [PATCH] Disable eval for pdfjs [SCI-10680] --- app/assets/javascripts/sitewide/pdf_preview.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/assets/javascripts/sitewide/pdf_preview.js b/app/assets/javascripts/sitewide/pdf_preview.js index dbaa0c758..55301ccde 100644 --- a/app/assets/javascripts/sitewide/pdf_preview.js +++ b/app/assets/javascripts/sitewide/pdf_preview.js @@ -115,7 +115,7 @@ var PdfPreview = (function() { function loadPdfDocument(canvas, page = 1) { - var loadingPdf = pdfjsLib.getDocument(canvas.dataset.pdfUrl); + var loadingPdf = pdfjsLib.getDocument({ url: canvas.dataset.pdfUrl, isEvalSupported: false }); $(canvas).data('load-attempts', $(canvas).data('load-attempts') + 1); loadingPdf.promise .then(function(pdfDocument) {