Skip to content

fix(desktop): enable the content security policy - #4614

Open
jmecom wants to merge 2 commits into
mainfrom
codex/security-desktop-csp
Open

fix(desktop): enable the content security policy#4614
jmecom wants to merge 2 commits into
mainfrom
codex/security-desktop-csp

Conversation

@jmecom

@jmecom jmecom commented Aug 3, 2026

Copy link
Copy Markdown
Collaborator

This change enables a Tauri content security policy that limits executable content to the packaged application and does not allow inline scripts.

Relay, media, asset, and Tauri IPC schemes remain available for desktop compatibility. The policy contains the impact of a future renderer injection; it does not itself remove an injection bug.

Testing

  • git diff --check origin/main...codex/security-desktop-csp
  • Rebased onto origin/main at 5c98932
  • Full CI pending

Originating Buzz thread: buzz://message?channel=3928fe05-df61-4b5d-b9c7-d623b9b10ea1&id=3c6c02312f763fbe0d2bfc33a6c1a362f91d0354f3d18b039cf7a0558c1439d1

Restrict executable content to the packaged application while retaining the relay, media, asset, and Tauri IPC schemes the desktop uses at runtime.

Co-authored-by: Jordan Mecom <jm@squareup.com>
Signed-off-by: Jordan Mecom <jm@squareup.com>
@jmecom
jmecom marked this pull request as ready for review August 3, 2026 21:00
@jmecom
jmecom requested a review from a team as a code owner August 3, 2026 21:00
The newly enabled policy broke two shipped features in packaged builds, and
neither `just dev` (loads the Vite devUrl) nor Playwright (`vite preview`)
enforces the CSP, so nothing caught it:

- `script-src 'self'` without `'wasm-unsafe-eval'` blocks WebAssembly
  instantiation. Shiki's default engine is Oniguruma-WASM (inlined, no fetch),
  so every code block silently fell back to plain text; MediaPipe selfie
  segmentation failed the same way.
- The MediaPipe wasm loader is fetched from jsDelivr. Allowlist that origin
  rather than vendoring the 32MB asset set.
- `rewriteRelayUrl` emits `buzz-media://localhost/...` until the loopback proxy
  port resolves, so cold-start media needs the custom scheme (mapped to
  `http://buzz-media.localhost` on Windows) in img/media/connect-src.

Drops the `asset:` sources: `assetProtocol` is not enabled and nothing calls
`convertFileSrc`. `connect-src` keeps blanket cleartext schemes — relay URLs
are user-supplied and plain `ws://` on any host is accepted, so `relayProbe`
would report reachable relays as dead.

Adds csp_tests.rs pinning the non-obvious sources, since the policy is
unenforceable in both local dev and the e2e suite.

Signed-off-by: Eli Foster <efoster@squareup.com>

@elifoster-block elifoster-block left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added tests and some extra additions in the CSP to cover items that would break without it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants