there was a simpler example on hn within the last week or two, but for example, json-rules-engine demonstrates how json might be a dynamic program, without ever needing to call eval or Function dynamic code: https://github.com/CacheControl/json-rules-engine
this would need to be extended with some html constructs. which is certainly possible.
or take evaljs and preload in some html functions!
> You might be working in a JavaScript environment where eval() isn't allowed (and you have a genuinely good reason why you want to use it). Maybe this'll slip under the radar.
https://github.com/marten-de-vries/evaljs
surely the people pitching these so called security measures grok just how many dump trucks of nonsense these so called protections they offer us are. about a week ago maybe even it would have sounded ok. but since that time, we've had a big announcement that wizer can now run spidermonkey js engine in webassembly. there's industrial grade js machinery we can run, free from these constraints, nested inside the web platform. with that, this v3 announcement is a week too late to hold even a drop of water. https://news.ycombinator.com/item?id=27370138
I believe they want to do something good too. but they are ineffectual & doing amazing amounts of damage in their grasp to give us this pretend fake security.