Skip to content

feat(runtime): scope external resource origins to published scripts - #594

Draft
marcodantonio-netsons wants to merge 1 commit into
CoreBunch:mainfrom
marcodantonio-netsons:feat/runtime-resource-origins
Draft

marcodantonio-netsons wants to merge 1 commit into
CoreBunch:mainfrom
marcodantonio-netsons:feat/runtime-resource-origins

Conversation

@marcodantonio-netsons

Copy link
Copy Markdown

User-authored scripts can load a third-party SDK but the published page's default CSP blocks its script, iframe or fetch destination. Add per-script HTTP(S) resource origins to the runtime settings and carry them through the build into published CSP, scoped to pages where that script actually emits a tag.

Authors can configure script, frame and connection origins in the code editor. Paths, credentials, wildcards and CSP keywords are rejected. Disabled scripts, excluded pages, failed builds and rejected script URLs grant no origins; connection grants retain same-origin access. No database migration is needed.

Validation: bun test (7,059 passing), bun run build, bun run lint, and git diff --check. Tests cover origin validation, editor corrections, classic/module builds, page scope, disabled/failed entries and CSP isolation. A local native-publisher browser preview loaded the real Turnstile SDK and produced a token with its localhost test key; no external form submission was sent.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant