diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 13:09:47 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 13:09:54 +0200 |
| commit | 87725dc7a2da27c2ca3b9e58af751f0e6f8c9de7 (patch) | |
| tree | 4bb433e12a959d497d537c5cf3abec993795daee /packages/meshbay-client/src | |
| parent | 2c6921aa2c35ffd41b6c453e6700574ef631ba2c (diff) | |
| download | meshbay-87725dc7a2da27c2ca3b9e58af751f0e6f8c9de7.tar.gz | |
fix: the page connects to its own origin and reCAPTCHA, nowhere else
connect-src drops https: and wss: in both policies. Checked against Google's
reCAPTCHA test keys: in Chrome widget, token and registration unchanged; in
Firefox the widget loads; no violation reported in either.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-client/src')
| -rw-r--r-- | packages/meshbay-client/src/main.js | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/packages/meshbay-client/src/main.js b/packages/meshbay-client/src/main.js index 80f49e4..5e1120b 100644 --- a/packages/meshbay-client/src/main.js +++ b/packages/meshbay-client/src/main.js @@ -133,7 +133,9 @@ const CSP = [ `img-src 'self' data: blob: ${RECAPTCHA_SRC}`, "media-src 'self' blob:", "font-src 'self'", - "connect-src 'self' https: wss:", + // Every hub call leaves from this process, so the page connects to nothing + // but its own files and reCAPTCHA; see the hub's webapp.CSP. + `connect-src 'self' ${RECAPTCHA_SRC}`, "worker-src 'self'", // `blob:` here and in `frame-src` are one thing, not two: the PDF preview. // |