From 87725dc7a2da27c2ca3b9e58af751f0e6f8c9de7 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Wed, 30 Sep 2026 13:09:47 +0200 Subject: fix: the page connects to its own origin and reCAPTCHA, nowhere else connect-src drops https: and wss: in both policies. Checked against Google's reCAPTCHA test keys: in Chrome widget, token and registration unchanged; in Firefox the widget loads; no violation reported in either. Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-hub/src/meshbay_hub/api/webapp.py | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/api/webapp.py') diff --git a/packages/meshbay-hub/src/meshbay_hub/api/webapp.py b/packages/meshbay-hub/src/meshbay_hub/api/webapp.py index 1d3bc7e..badbdda 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/webapp.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/webapp.py @@ -90,7 +90,13 @@ CSP = "; ".join([ f"img-src 'self' data: blob: {_RECAPTCHA_SRC}", "media-src 'self' blob:", "font-src 'self'", - "connect-src 'self' https: wss:", + # The page talks to its own origin and nothing else — the hub, the node + # arrives over WebRTC, which this directive does not govern. reCAPTCHA's + # two origins are the only others, kept so its script may call home from + # this page; the register and reset views were driven in Chrome and Firefox + # against Google's test keys with this line and reported no violation. + # `https: wss:` let an injected script post anything anywhere. + f"connect-src 'self' {_RECAPTCHA_SRC}", "worker-src 'self'", # `object-src` exists for one thing, and `frame-src`'s `blob:` for the same # thing: previewing a PDF without writing it anywhere. -- cgit v1.2.3