Skip to content

fix(desktop): enable the content security policy - #4614

Open
jmecom wants to merge 1 commit into
mainfrom
codex/security-desktop-csp
Open

fix(desktop): enable the content security policy#4614
jmecom wants to merge 1 commit into
mainfrom
codex/security-desktop-csp

Conversation

@jmecom

@jmecom jmecom commented Aug 3, 2026

Copy link
Copy Markdown
Collaborator

This change enables a Tauri content security policy that limits executable content to the packaged application and does not allow inline scripts.

Relay, media, asset, and Tauri IPC schemes remain available for desktop compatibility. The policy contains the impact of a future renderer injection; it does not itself remove an injection bug.

Testing

  • git diff --check origin/main...codex/security-desktop-csp
  • Rebased onto origin/main at 5c98932
  • Full CI pending

Originating Buzz thread: buzz://message?channel=3928fe05-df61-4b5d-b9c7-d623b9b10ea1&id=3c6c02312f763fbe0d2bfc33a6c1a362f91d0354f3d18b039cf7a0558c1439d1

Restrict executable content to the packaged application while retaining the relay, media, asset, and Tauri IPC schemes the desktop uses at runtime.

Co-authored-by: Jordan Mecom <jm@squareup.com>
Signed-off-by: Jordan Mecom <jm@squareup.com>
@jmecom
jmecom marked this pull request as ready for review August 3, 2026 21:00
@jmecom
jmecom requested a review from a team as a code owner August 3, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant