From 87725dc7a2da27c2ca3b9e58af751f0e6f8c9de7 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 13:09:47 +0200 Subject: fix: the page connects to its own origin and reCAPTCHA, nowhere else connect-src drops https: and wss: in both policies. Checked against Google's reCAPTCHA test keys: in Chrome widget, token and registration unchanged; in Firefox the widget loads; no violation reported in either. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-client/src/main.js | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-client/src') diff --git a/packages/meshbay-client/src/main.js b/packages/meshbay-client/src/main.js index 80f49e4..5e1120b 100644 --- a/packages/meshbay-client/src/main.js +++ b/packages/meshbay-client/src/main.js @@ -133,7 +133,9 @@ const CSP = [ `img-src 'self' data: blob: ${RECAPTCHA_SRC}`, "media-src 'self' blob:", "font-src 'self'", - "connect-src 'self' https: wss:", + // Every hub call leaves from this process, so the page connects to nothing + // but its own files and reCAPTCHA; see the hub's webapp.CSP. + `connect-src 'self' ${RECAPTCHA_SRC}`, "worker-src 'self'", // `blob:` here and in `frame-src` are one thing, not two: the PDF preview. // -- cgit v1.2.3