php / php/php-src

phpinfo() doesn't play nicely with strict CSPs

Aperta
#20,522 6 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Feature Status: Needs Triage
Lingua principale
C
Stelle
40.4k
Fork
8.1k
Merge medio
2g 13h
PR unite (30g)
96

Descrizione

Description

The output generated by phpinfo() includes inline styles and data: URLs for two images. While this is self-contained, it's incompatible with Content-Security-Policy headers that are configured securely, specifically, if your CSP doesn't include 'unsafe-inline' for style-src and data: for img-src, the output looks bad:

Image

Two of the 6 locations in the output (i.e. not many) that uses inline styles:

                  <tr>
                    <td class="e">highlight.comment</td>
                    <td class="v">
                        <span style="color: #FF8000">#FF8000</span>
                    </td>
                    <td class="v">
                        <span style="color: #FF8000">#FF8000</span>
                    </td>
                </tr>

styling like this would need to be turned into classes, though as you can see this output already makes use of classes, so this is trivial to fix.

A good way to resolve this would be to extend phpinfo so that it can serve these resources separately depending on the request context, so for example a request that contains a request param like phpinfo=styles could serve the style sheet, and phpinfo=logo could serve a logo image.

This approach would be compatible with a super-strict CSP like this (in fact there's nothing preventing phpinfo from generating this header itself):

Content-Security-Policy: default-src 'none'; image-src 'self'; style-src 'self';

The downside of this approach is that it would end up making multiple requests to serve the same page content. I don't know if there is a way that the existing approach could be preserved while allowing for this more secure approach as well.

An alternative would be for the page to generate CSP nonces or SRI hashes for the data and style elements. That's probably more complicated, though it would allow the page to remain self-contained.

Since phpinfo is a development feature, it's not very important to fix this, but it's an easy opportunity to encourage secure development practices while also making the generated page immune to injections.

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Parti dal punto di ingresso phpinfo() e traccia il modo in cui vengono generati il relativo HTML, gli stili inline e gli URL delle immagini data:. Confronta i possibili approcci per la gestione delle risorse e gli approcci basati su nonce o hash con la CSP rigorosa descritta nell’issue. Il lavoro è completato quando la pagina generata viene visualizzata correttamente senza autorizzazioni unsafe-inline o data:.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
c, php
Ambito
backend, security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Ferma
Chiarezza
Da chiarire
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.