JavaScriptBlockedForUrls

Block JavaScript on these sites

Supported on:

  • Chrome (Windows) since version 11

Description:

Setting the policy lets you set a list of URL patterns that specify the sites that can't run JavaScript.

Leaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies.

Wildcards, *, are allowed.

Note that this policy blocks JavaScript based on whether the origin of the top-level document (usually the page URL that is also displayed in the address bar) matches any of the patterns. Therefore this policy is not appropriate for mitigating web supply-chain attacks. For example, supplying the pattern "https://[*.]foo.com/" will not prevent a page hosted on, say, https://example.com from running a script loaded from https://www.foo.com/example.js. Furthermore, supplying the pattern "https://example.com/" will not prevent a document from https://example.com from running scripts if it is not the top-level document, but embedded as a sub-frame into a page hosted on another origin, say, https://www.bar.com.

Supported features:

  • Applied to browser without restart. Note that some ongoing tasks may not be affected.
  • Applied at Samsung Browser profile level.

Data type:

List of strings

Windows registry location:

Software\Policies\Samsung\Internet\JavaScriptBlockedForUrls

Example value:

Software\Policies\Samsung\Internet\JavaScriptBlockedForUrls\1 = https://www.example.com
Software\Policies\Samsung\Internet\JavaScriptBlockedForUrls\2 = [*.]example.edu

More policies under Content settings: