Every page breaches the content security policy, because htmx injects a stylesheet #68
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#68
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What happens
Every page Postulo serves logs a content security policy violation in the browser console:
Found while driving the passkey flow through a real browser with the production policy on.
It is on the dashboard, the sign-in page and the password reset page too, so it has nothing
to do with passkeys and has been there since htmx was vendored.
Why
htmx ships with
includeIndicatorStyles: true, which makes it inject a<style>elementinto the head as it starts, carrying the rules for
.htmx-indicator. Production setsstyle-src 'self'with nounsafe-inline, so the browser refuses it.The injected rules are redundant:
assets/css/app.cssalready defines.htmx-indicatorand the
.htmx-requestpair, deliberately, because the policy forbids exactly this.Why it matters more than a console message
violation on every page has one that is not quite true. Anybody hardening their instance,
or pointing a reporting endpoint at it, sees noise that means nothing.
cannot be written while every page breaches it, which is precisely how this went unnoticed.
Fix
Tell htmx not to, with a meta tag in
base.html— an attribute, which the policy allows:Then a browser test that visits a few pages with the production policy applied and fails on
any violation logged to the console. That is the part that keeps it fixed.
Classification
Bug, security. Not breaking: the indicator styling is already in Postulo's own stylesheet.