Read a Markdown file as the document it is
A .md previewed as its own source, which is reading the punctuation rather than the notes. It now opens rendered, with Rendered | Source in the dialog footer for anyone who wants what the file actually says. Markdown only; a .txt has nothing to toggle between. Rendering is `marked`, sanitised by DOMPurify -- the one the app already carries for mail. Markdown is not a safe subset of anything: raw HTML passes through it by design, so a <script> in a file somebody uploaded or shared into the account is a script tag unless something takes it out. Images become links rather than pictures. An image in a Markdown file is either a relative path, which has no base to resolve against here, or a URL somewhere else, which fetches on open and tells that server the file was read -- the tracking pixel this app blocks in mail. The link keeps the alt text and the address, so nothing vanishes silently. Fixes the PDF preview while here, which never worked: securityHeaders put X-Frame-Options: DENY on every response including the blob route, so the iframe showed Chrome's "refused to connect" where the file should have been -- in Files today and in mail attachments long before that. The middleware now leaves a header the route has set, and a PDF served inline says SAMEORIGIN. Nothing else on the server is framable.
This commit is contained in:
@@ -88,3 +88,22 @@ test("a Sieve script larger than a compressing hop's threshold survives the prox
|
||||
origin.close();
|
||||
}
|
||||
});
|
||||
|
||||
test("only a PDF blob may be framed, and only by us", async () => {
|
||||
/*
|
||||
* The PDF preview is an iframe, and the blanket X-Frame-Options: DENY on
|
||||
* every response blocked it -- the dialog showed Chrome's "refused to
|
||||
* connect" where the file should have been. The middleware now leaves a
|
||||
* header a route has already set, so this pins both halves: the exception
|
||||
* exists, and it did not become the rule.
|
||||
*/
|
||||
const app = createApp();
|
||||
const health = await app.request("/api/health");
|
||||
assert.equal(health.headers.get("x-frame-options"), "DENY");
|
||||
|
||||
const { securityHeadersFor } = await import("./app.js");
|
||||
assert.equal(securityHeadersFor("application/pdf", true), "SAMEORIGIN");
|
||||
assert.equal(securityHeadersFor("application/pdf", false), "DENY");
|
||||
assert.equal(securityHeadersFor("image/png", true), "DENY");
|
||||
assert.equal(securityHeadersFor("text/html", true), "DENY");
|
||||
});
|
||||
|
||||
+25
-2
@@ -82,7 +82,9 @@ const securityHeaders: MiddlewareHandler = async (c, next) => {
|
||||
await next();
|
||||
const h = c.res.headers;
|
||||
h.set("X-Content-Type-Options", "nosniff");
|
||||
h.set("X-Frame-Options", "DENY");
|
||||
/* A route that must be framable says so; everything else is DENY. The blob
|
||||
route is the only one, and only for PDFs -- see the note there. */
|
||||
if (!h.has("X-Frame-Options")) h.set("X-Frame-Options", "DENY");
|
||||
h.set("Referrer-Policy", "no-referrer");
|
||||
h.set("Permissions-Policy", "camera=(), microphone=(), geolocation=(), payment=(), usb=()");
|
||||
h.set("Cross-Origin-Opener-Policy", "same-origin");
|
||||
@@ -538,7 +540,19 @@ export function createApp(): Hono<Env> {
|
||||
);
|
||||
headers.set("X-Content-Type-Options", "nosniff");
|
||||
// Sandbox everything except the browser's built-in PDF viewer (which needs scripts to render).
|
||||
if (!(safeInline && type === "application/pdf")) {
|
||||
if (securityHeadersFor(type, safeInline) === "SAMEORIGIN") {
|
||||
/*
|
||||
* The one response on the server that may be framed.
|
||||
*
|
||||
* A PDF is shown in an iframe -- it is its own document and the app
|
||||
* cannot lay it out -- and the blanket X-Frame-Options: DENY above
|
||||
* blocked that, so the preview showed Chrome's "refused to connect"
|
||||
* instead of the file. SAMEORIGIN, not a relaxation to any site: the
|
||||
* frame is ours, on our origin, and the app's own CSP already says
|
||||
* frame-src 'self'. Nothing else here is framed, so nothing else asks.
|
||||
*/
|
||||
headers.set("X-Frame-Options", "SAMEORIGIN");
|
||||
} else {
|
||||
headers.set("Content-Security-Policy", "sandbox; default-src 'none'; style-src 'unsafe-inline'; img-src data:");
|
||||
}
|
||||
headers.set("Cache-Control", "private, max-age=3600");
|
||||
@@ -697,6 +711,15 @@ function sanitizeContentType(ct: string): string {
|
||||
return lower || "application/octet-stream";
|
||||
}
|
||||
|
||||
/**
|
||||
* What X-Frame-Options a blob response carries. Exported so the rule is
|
||||
* testable without standing up an upstream: a PDF served inline may be framed
|
||||
* by us and nothing else may be framed at all.
|
||||
*/
|
||||
export function securityHeadersFor(type: string, safeInline: boolean): "SAMEORIGIN" | "DENY" {
|
||||
return safeInline && type.split(";")[0]!.trim() === "application/pdf" ? "SAMEORIGIN" : "DENY";
|
||||
}
|
||||
|
||||
function isInlineSafe(type: string): boolean {
|
||||
const t = type.split(";")[0]!.trim();
|
||||
return (
|
||||
|
||||
Reference in New Issue
Block a user