Uploaded image for project: 'Nuxeo Web UI'
  1. Nuxeo Web UI
  2. WEBUI-1282

Allow Content Security Policy without "script-src data:"

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: In Review
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: 3.0.0
    • Fix Version/s: 3.0.x, 3.1.x
    • Component/s: UI

      Description

      In Content Security Policies (CSP), the data: directive of script-src can be considered insecure - similar to usages of unsafe-eval and unsafe-inline.

      While WEBUI-60 allows for the removal of unsafe-eval and unsafe-inline from the CSP by disabling org.nuxeo.web.ui.expressions.eval, this does not prevent browser errors from occurring when the data: directive is removed. There should be a mechanism to allow Polymer scripts to execute without the need for this policy directive.

      Steps to Reproduce:

      1. Set the following contribution (via XML extension or configuration template):

      <require>org.nuxeo.ecm.platform.web.common.requestcontroller.service.RequestControllerService.defaultContrib</require>
      <extension target="org.nuxeo.ecm.platform.web.common.requestcontroller.service.RequestControllerService" point="responseHeaders">
         <header name="Content-Security-Policy">default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: www.nuxeo.com; font-src * data:; media-src 'self'; frame-src 'self'; frame-ancestors 'self'; object-src 'none';</header>
      </extension>
      
      <extension target="org.nuxeo.runtime.ConfigurationService" point="configuration">
         <property name="org.nuxeo.web.ui.expressions.eval">false</property>
      </extension>

      2. Login to the instance via Web UI

      Expected behavior: nuxeo-home loads; page is traversible

      Actual behavior: nuxeo-home is blank; several errors outputted in the browser console (see screenshot).

      Refused to load the script '<URL>' because it violates the following Content Security Policy directive: "script-src 'self'". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.
      

        Attachments

        1. apidoc.png
          1.10 MB
          Alok Ranjan
        2. Documentation of Removing script-src data Directive from Content Security.pdf
          218 kB
          rakesh.kumarsingh@contractors.onbase.com
        3. refused-to-load-script.PNG
          487 kB
          Henry Miskaryan
        4. Screenshot 2024-07-16 at 10.39.59 AM.png
          981 kB
          Alok Ranjan
        5. spreadsheet.png
          1.82 MB
          Alok Ranjan

          Issue Links

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                9 Start watching this issue

                Dates

                • Created:
                  Updated:

                  Time Tracking

                  Estimated:
                  Original Estimate - 1 day Original Estimate - 1 day
                  1d
                  Remaining:
                  Time Spent - 4 days, 5 minutes Remaining Estimate - 3 hours
                  3h
                  Logged:
                  Time Spent - 4 days, 5 minutes Remaining Estimate - 3 hours
                  4d 5m