aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api/webapp.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-01 21:51:25 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-01 21:51:25 +0200
commit799d87999c8324564dce5159191532e008dd93d2 (patch)
tree5ff1816f18625dfece9eb67fa06c7b25fdece4f8 /packages/meshbay-hub/src/meshbay_hub/api/webapp.py
parent8a6294b0412a86f378c6e2e937c28de64a903c91 (diff)
parent1e6db7d23c70b7bd7e1422f09911b3645f0fb2e2 (diff)
downloadmeshbay-799d87999c8324564dce5159191532e008dd93d2.tar.gz
Merge branch 'fix/third-review-h1-h2-m1-m6'
Third security review (docs/third-review.md) plus its remediation. Fixed and verified: - H1 moderator could grant admin / hard-revoke → handler split by field - H2 unauthenticated 2-report global blocklist → auth + distinct reporters + rate limit + refused when public groups are off - M1 registration reCAPTCHA was inert → gate unconditional; the desktop client's CSP allows the widget - M2 QUIC chat/stream handlers lagged WebRTC → brought to parity; the QUIC listener is now off by default ([node] quic_enabled) - M3 link-preview SSRF gaps → rate limit + port allowlist + connect-address re-check + decompression-bomb guard - M4 federated peer over-trust → source bound to the signer, push capped, revocation prunes the peer's own entries, replay rejected - M5 no CSP / security headers on the SPA → middleware; verified against the live app with no violations Withdrawn: - M6 add_group_member accepting node tokens is deliberate (commit 0443cf8, the CLI invite flow). The "fix" broke that flow on the deployed hub and was reverted. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011pG75yGK3NthNfyjH74omG
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/webapp.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/webapp.py31
1 files changed, 29 insertions, 2 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/webapp.py b/packages/meshbay-hub/src/meshbay_hub/api/webapp.py
index 0821809..6dfd3ed 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/webapp.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/webapp.py
@@ -22,7 +22,8 @@ STATIC_DIR = Path(__file__).parent.parent / "static"
router = APIRouter(tags=["webapp"])
# Assets the shell pulls in, in load order. Everything else is imported by
-# app.js and rides on the same query string via window.__MB_ASSET_V.
+# app.js from a relative path, which inherits the `/a/<hash>/` prefix the shell
+# loaded app.js under — so the whole module graph moves together.
# Every module the page loads. A file missing from here is a file whose change
# does not move the URL, so a browser holding the old one never asks for it —
# which is the failure this list exists to prevent, and it is silent.
@@ -77,6 +78,33 @@ ASSET_V = _asset_version()
_NO_STORE = {"Cache-Control": "no-store"}
+# Content-Security-Policy for the whole hub, applied by a middleware in app.py.
+#
+# This is the *same* policy the desktop client's protocol handler already sends
+# for these exact UI files (`meshbay-client/src/main.js`), plus the two reCAPTCHA
+# hosts the sign-up widget loads its script, challenge iframe and images from.
+# `'unsafe-inline'` is style-only — htm/preact set inline `style=` attributes
+# everywhere; nothing inline executes, and the shell below carries no inline
+# `<script>`. `'wasm-unsafe-eval'` is required for the Argon2id WASM. The hub's
+# own origin is deliberately absent from `script-src`: a response it returns is
+# never executed, which is the point of T3.
+_RECAPTCHA_SRC = "https://www.google.com https://www.gstatic.com"
+CSP = "; ".join([
+ "default-src 'none'",
+ f"script-src 'self' 'wasm-unsafe-eval' {_RECAPTCHA_SRC}",
+ "style-src 'self' 'unsafe-inline'",
+ f"img-src 'self' data: blob: {_RECAPTCHA_SRC}",
+ "media-src 'self' blob:",
+ "font-src 'self'",
+ "connect-src 'self' https: wss:",
+ "worker-src 'self'",
+ f"frame-src {_RECAPTCHA_SRC}",
+ "frame-ancestors 'none'",
+ "base-uri 'none'",
+ "form-action 'none'",
+])
+
+
@router.get("/app", response_class=HTMLResponse)
async def app_root():
return HTMLResponse(_HTML, headers=_NO_STORE)
@@ -109,7 +137,6 @@ _HTML = """\
and app.js's own relative imports inherit the prefix, which is the only
way the module graph is guaranteed not to be a mixture of two builds.
See _asset_version() and VersionedStatics. -->
- <script>window.__MB_ASSET_V = "{v}";</script>
<!-- Argon2id (WebAssembly, inlined) — WebCrypto has no memory-hard KDF, and the
keypair bundle needs one: it is protected by the passphrase alone and sits
on every node its owner joins (C4). Vendored, see static/vendor/PROVENANCE.md -->