fix(desktop): enable the content security policy - #4614
Open
jmecom wants to merge 2 commits into
Open
Conversation
Restrict executable content to the packaged application while retaining the relay, media, asset, and Tauri IPC schemes the desktop uses at runtime. Co-authored-by: Jordan Mecom <jm@squareup.com> Signed-off-by: Jordan Mecom <jm@squareup.com>
jmecom
marked this pull request as ready for review
August 3, 2026 21:00
The newly enabled policy broke two shipped features in packaged builds, and neither `just dev` (loads the Vite devUrl) nor Playwright (`vite preview`) enforces the CSP, so nothing caught it: - `script-src 'self'` without `'wasm-unsafe-eval'` blocks WebAssembly instantiation. Shiki's default engine is Oniguruma-WASM (inlined, no fetch), so every code block silently fell back to plain text; MediaPipe selfie segmentation failed the same way. - The MediaPipe wasm loader is fetched from jsDelivr. Allowlist that origin rather than vendoring the 32MB asset set. - `rewriteRelayUrl` emits `buzz-media://localhost/...` until the loopback proxy port resolves, so cold-start media needs the custom scheme (mapped to `http://buzz-media.localhost` on Windows) in img/media/connect-src. Drops the `asset:` sources: `assetProtocol` is not enabled and nothing calls `convertFileSrc`. `connect-src` keeps blanket cleartext schemes — relay URLs are user-supplied and plain `ws://` on any host is accepted, so `relayProbe` would report reachable relays as dead. Adds csp_tests.rs pinning the non-obvious sources, since the policy is unenforceable in both local dev and the e2e suite. Signed-off-by: Eli Foster <efoster@squareup.com>
elifoster-block
approved these changes
Aug 4, 2026
elifoster-block
left a comment
There was a problem hiding this comment.
Added tests and some extra additions in the CSP to cover items that would break without it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This change enables a Tauri content security policy that limits executable content to the packaged application and does not allow inline scripts.
Relay, media, asset, and Tauri IPC schemes remain available for desktop compatibility. The policy contains the impact of a future renderer injection; it does not itself remove an injection bug.
Testing
git diff --check origin/main...codex/security-desktop-csporigin/mainat5c98932Originating Buzz thread:
buzz://message?channel=3928fe05-df61-4b5d-b9c7-d623b9b10ea1&id=3c6c02312f763fbe0d2bfc33a6c1a362f91d0354f3d18b039cf7a0558c1439d1