diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-01 20:03:03 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-01 20:03:03 +0200 |
| commit | f2915bc7b1550b80cadfa36f5910223106cb3bfe (patch) | |
| tree | 34fa6760db608968057feac31b5f38bcca28bfa4 /packages/meshbay-hub/src/meshbay_hub/api/webapp.py | |
| parent | 24d29e910c8d1649a1cd51969f27b921b94d97e3 (diff) | |
| download | meshbay-f2915bc7b1550b80cadfa36f5910223106cb3bfe.tar.gz | |
fix(hub): send a CSP and protective headers on every response
The SPA shell and its assets went out with no Content-Security-Policy
and no X-Content-Type-Options / Referrer-Policy / X-Frame-Options — so
an injection that reached the SPA (rendered third-party OpenGraph
data, a federated group name, chat content) had nothing stopping it
from loading more code or exfiltrating to any host, and the page
could be framed by any site.
A middleware in `create_app` now adds all four to every response.
`webapp.CSP` is deliberately the *same* policy the desktop client's
protocol handler already enforces on these exact UI files, plus the
two reCAPTCHA hosts the sign-up widget needs: `default-src 'none'`,
`script-src 'self' 'wasm-unsafe-eval' <recaptcha>` (the hub's own
origin is not a script source — T3), `style-src 'self'
'unsafe-inline'` (htm/preact inline `style=` only, nothing executes),
`connect-src 'self' https: wss:`, `frame-ancestors 'none'`,
`base-uri 'none'`, `form-action 'none'`.
The shell's dead `<script>window.__MB_ASSET_V = ...</script>` is
removed (nothing has ever read it) so `script-src` needs no inline
allowance.
Needs verification against the running SPA — a mis-tuned CSP shows as
a blank page — but it matches a policy already proven with these
files under Electron.
Second-review L5 / third-review M5.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011pG75yGK3NthNfyjH74omG
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/webapp.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/api/webapp.py | 31 |
1 files changed, 29 insertions, 2 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/webapp.py b/packages/meshbay-hub/src/meshbay_hub/api/webapp.py index 0821809..6dfd3ed 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/webapp.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/webapp.py @@ -22,7 +22,8 @@ STATIC_DIR = Path(__file__).parent.parent / "static" router = APIRouter(tags=["webapp"]) # Assets the shell pulls in, in load order. Everything else is imported by -# app.js and rides on the same query string via window.__MB_ASSET_V. +# app.js from a relative path, which inherits the `/a/<hash>/` prefix the shell +# loaded app.js under — so the whole module graph moves together. # Every module the page loads. A file missing from here is a file whose change # does not move the URL, so a browser holding the old one never asks for it — # which is the failure this list exists to prevent, and it is silent. @@ -77,6 +78,33 @@ ASSET_V = _asset_version() _NO_STORE = {"Cache-Control": "no-store"} +# Content-Security-Policy for the whole hub, applied by a middleware in app.py. +# +# This is the *same* policy the desktop client's protocol handler already sends +# for these exact UI files (`meshbay-client/src/main.js`), plus the two reCAPTCHA +# hosts the sign-up widget loads its script, challenge iframe and images from. +# `'unsafe-inline'` is style-only — htm/preact set inline `style=` attributes +# everywhere; nothing inline executes, and the shell below carries no inline +# `<script>`. `'wasm-unsafe-eval'` is required for the Argon2id WASM. The hub's +# own origin is deliberately absent from `script-src`: a response it returns is +# never executed, which is the point of T3. +_RECAPTCHA_SRC = "https://www.google.com https://www.gstatic.com" +CSP = "; ".join([ + "default-src 'none'", + f"script-src 'self' 'wasm-unsafe-eval' {_RECAPTCHA_SRC}", + "style-src 'self' 'unsafe-inline'", + f"img-src 'self' data: blob: {_RECAPTCHA_SRC}", + "media-src 'self' blob:", + "font-src 'self'", + "connect-src 'self' https: wss:", + "worker-src 'self'", + f"frame-src {_RECAPTCHA_SRC}", + "frame-ancestors 'none'", + "base-uri 'none'", + "form-action 'none'", +]) + + @router.get("/app", response_class=HTMLResponse) async def app_root(): return HTMLResponse(_HTML, headers=_NO_STORE) @@ -109,7 +137,6 @@ _HTML = """\ and app.js's own relative imports inherit the prefix, which is the only way the module graph is guaranteed not to be a mixture of two builds. See _asset_version() and VersionedStatics. --> - <script>window.__MB_ASSET_V = "{v}";</script> <!-- Argon2id (WebAssembly, inlined) — WebCrypto has no memory-hard KDF, and the keypair bundle needs one: it is protected by the passphrase alone and sits on every node its owner joins (C4). Vendored, see static/vendor/PROVENANCE.md --> |