dequelabs / dequelabs/axe-core

axe-core and Axe extensions fail on pages with a "sandbox" CSP directive

Open
#3,592 6 comments 0 reactions 0 assignees View on GitHub
APIs extension
Dominant language
JavaScript
Stars
7.5k
Forks
933
Avg merge
2d 23h
Merged PRs (30d)
17

Description

### Product

axe-core

### Product Version

4.4.3

### Lastest Version

- [X] I have tested the issue with the latest version of the product

### Issue Description

### Expectation

I expected Axe to audit a site that has a `sandbox` CSP directive, without an `allow-scripts` parameter.

### Actual

axe-core-npm, Axe DevTools for Chrome, Axe DevTools for Firefox, and Webhint's Axe audits all fail to analyze the page.

### How to Reproduce

All of the following test-cases involve running an audit on https://seirdy.one/

#### axe-core-npm

Run the the latest version of axe-core to get the following result:

```
Testing https://seirdy.one/ ... please wait, this may take a minute.
Error: TimeoutError: Waiting for at least one element to be located By(css selector, .deque-axe-is-ready)
Wait timed out after 10063ms
at /home/rkumar/Executables/npm/lib/node_modules/@axe-core/cli/node_modules/selenium-webdriver/lib/webdriver.js:906:17
at processTicksAndRejections (node:internal/process/task_queues:96:5) {
remoteStacktrace: ''
}
Please report the problem to: https://github.com/dequelabs/axe-core-npm/issues/
```

#### Axe-DevTools for Chrome

Run the latest version of Axe Devtools for Chromium/Edge and get a "We're sorry, but axe DevTools was unable to analyze the current tab." message (see screenshot). The error remains with or without granting access to `file://` urls.

![Axe-devtools error page states that Axe doesn't have page access](https://user-images.githubusercontent.com/44756978/183770854-9861039d-0d15-49d8-b61e-33dd2dd96a1a.png)

#### Axe-DevTools for Firefox

Run the latest version of Axe DevTools for Firefox and get the "analyzing your page" spinner. The spinner seems to persist indefinitely.

#### axe-core dependent: Webhint

Run Webhint with Puppeteer, Axe hints, and debug-logging enabled and receive the following output:

Debug logs

```
hint:engine Hint axe/parsing timeout +2m
hint:engine Total runtime 123003 +0ms
hint:path:to:@hint+connector-puppeteer@2.5.19_hint@7.1.1:node_modules:@hint:connector-puppeteer:dist:src:connector Removing all pending event listeners (2) +2m
hint:path:to:@hint+connector-puppeteer@2.5.19_hint@7.1.1:node_modules:@hint:connector-puppeteer:dist:src:connector Removing event listeners for error,pageerror +0ms
hint:path:to:@hint+connector-puppeteer@2.5.19_hint@7.1.1:node_modules:@hint:connector-puppeteer:dist:src:connector Removing handler for event "error" +0ms
hint:path:to:@hint+connector-puppeteer@2.5.19_hint@7.1.1:node_modules:@hint:connector-puppeteer:dist:src:connector Removing handler for event "pageerror" +0ms
hint:lifecycle Closing +2m
hint:lifecycle Closing page +0ms
hint:lifecycle Remaining pages: 0 +0ms
hint:path:to:@hint+formatter-codeframe@3.1.31_hint@7.1.1:node_modules:@hint:formatter-codeframe:dist:src:formatter Formatting results +0ms
Running axe-core failed: Protocol error (Runtime.evaluate): Target closed.
ProtocolError: Protocol error (Runtime.evaluate): Target closed.
at /home/rkumar/.local/share/pnpm/global/5/.pnpm/puppeteer-core@13.7.0/node_modules/puppeteer-core/lib/cjs/puppeteer/common/Connection.js:230:24
at new Promise ()
at CDPSession.send (/home/rkumar/.local/share/pnpm/global/5/.pnpm/puppeteer-core@13.7.0/node_modules/puppeteer-core/lib/cjs/puppeteer/common/Connection.js:226:16)
at ExecutionContext._evaluateInternal (/home/rkumar/.local/share/pnpm/global/5/.pnpm/puppeteer-core@13.7.0/node_modules/puppeteer-core/lib/cjs/puppeteer/common/ExecutionContext.js:166:18)
at ExecutionContext.evaluate (/home/rkumar/.local/share/pnpm/global/5/.pnpm/puppeteer-core@13.7.0/node_modules/puppeteer-core/lib/cjs/puppeteer/common/ExecutionContext.js:110:27)
at DOMWorld.evaluate (/home/rkumar/.local/share/pnpm/global/5/.pnpm/puppeteer-core@13.7.0/node_modules/puppeteer-core/lib/cjs/puppeteer/common/DOMWorld.js:97:24)
at runNextTicks (node:internal/process/task_queues:61:5)
at processImmediate (node:internal/timers:437:9)
hint:cli:analyze Total runtime: 123159ms +2m
```

### Additional context

Possibly-related issues in other/upstream projects:

- https://github.com/GoogleChrome/lighthouse/issues/11925
- https://bugs.chromium.org/p/chromium/issues/detail?id=1222763

In my tests, an `allow-scripts` parameter to the `sandbox` directive fixed Axe DevTools for Chrome, Axe DevTools for Firefox, and Webhint. However, the same issue was still present in axe-core-npm.

### Current workarounds

My current workaround is to run axe-core-npm on a local version of my site without a `sandbox` CSP directive, and to run Webhint and Axe DevTools on a staging site that has the `allow-scripts` parameter.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.