aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-client/src
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 13:09:47 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 13:09:54 +0200
commit87725dc7a2da27c2ca3b9e58af751f0e6f8c9de7 (patch)
tree4bb433e12a959d497d537c5cf3abec993795daee /packages/meshbay-client/src
parent2c6921aa2c35ffd41b6c453e6700574ef631ba2c (diff)
downloadmeshbay-87725dc7a2da27c2ca3b9e58af751f0e6f8c9de7.tar.gz
fix: the page connects to its own origin and reCAPTCHA, nowhere else
connect-src drops https: and wss: in both policies. Checked against Google's reCAPTCHA test keys: in Chrome widget, token and registration unchanged; in Firefox the widget loads; no violation reported in either. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-client/src')
-rw-r--r--packages/meshbay-client/src/main.js4
1 files changed, 3 insertions, 1 deletions
diff --git a/packages/meshbay-client/src/main.js b/packages/meshbay-client/src/main.js
index 80f49e4..5e1120b 100644
--- a/packages/meshbay-client/src/main.js
+++ b/packages/meshbay-client/src/main.js
@@ -133,7 +133,9 @@ const CSP = [
`img-src 'self' data: blob: ${RECAPTCHA_SRC}`,
"media-src 'self' blob:",
"font-src 'self'",
- "connect-src 'self' https: wss:",
+ // Every hub call leaves from this process, so the page connects to nothing
+ // but its own files and reCAPTCHA; see the hub's webapp.CSP.
+ `connect-src 'self' ${RECAPTCHA_SRC}`,
"worker-src 'self'",
// `blob:` here and in `frame-src` are one thing, not two: the PDF preview.
//