phpinfo() doesn't play nicely with strict CSPs
Personne n'a encore pris cette issue.
- Langage dominant
- C
- Étoiles
- 40.4k
- Forks
- 8.1k
- Merge moyen
- 2 j 13 h
- PR mergées (30 j)
- 96
Description
Description
The output generated by phpinfo() includes inline styles and data: URLs for two images. While this is self-contained, it's incompatible with Content-Security-Policy headers that are configured securely, specifically, if your CSP doesn't include 'unsafe-inline' for style-src and data: for img-src, the output looks bad:
Two of the 6 locations in the output (i.e. not many) that uses inline styles:
<tr>
<td class="e">highlight.comment</td>
<td class="v">
<span style="color: #FF8000">#FF8000</span>
</td>
<td class="v">
<span style="color: #FF8000">#FF8000</span>
</td>
</tr>
styling like this would need to be turned into classes, though as you can see this output already makes use of classes, so this is trivial to fix.
A good way to resolve this would be to extend phpinfo so that it can serve these resources separately depending on the request context, so for example a request that contains a request param like phpinfo=styles could serve the style sheet, and phpinfo=logo could serve a logo image.
This approach would be compatible with a super-strict CSP like this (in fact there's nothing preventing phpinfo from generating this header itself):
Content-Security-Policy: default-src 'none'; image-src 'self'; style-src 'self';
The downside of this approach is that it would end up making multiple requests to serve the same page content. I don't know if there is a way that the existing approach could be preserved while allowing for this more secure approach as well.
An alternative would be for the page to generate CSP nonces or SRI hashes for the data and style elements. That's probably more complicated, though it would allow the page to remain self-contained.
Since phpinfo is a development feature, it's not very important to fix this, but it's an easy opportunity to encourage secure development practices while also making the generated page immune to injections.
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez au point d’entrée phpinfo() et retracez la manière dont sont générés son HTML, ses styles inline et ses URL d’images data:. Comparez les différentes approches possibles de fourniture des ressources ainsi que les approches fondées sur un nonce ou un hash avec la CSP stricte décrite dans l’issue. C’est terminé lorsque la page générée s’affiche correctement sans autorisations unsafe-inline ni data:.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- c, php
- Domaine
- backend, security
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- À l'abandon
- Clarté
- À clarifier
- Accessibilité débutants
- 35/100