Output of renderer 'notebook' violates Content Security Policy
Ninguém assumiu esta issue ainda.
- Linguagem predominante
- Python
- Estrelas
- 18.8k
- Forks
- 2.8k
- Merge médio
- 16h 26min
- PRs com merge (30d)
- 21
Descrição
Setup description
We have plotly.py setup with pio.renderers.default = "notebook" and we use nbconvert 6.5 to convert executed notebooks to HTML reports with input cells stripped out. These HTMLs are served by a simple node.js front end that has Content Security Policies for script-src setup due to security requirements.
Issue description
The exported HTML contains inline script tags one of which has plotly.js and its dependencies. One of the dependencies seems to violate our script-src Content Security Policy as it is using eval(), new Function(), setTimeout([string], ...) and setInterval([string], ...) for evaluating strings Reference
CSP Error from Chrome:
- Content Security Policy of your site blocks the use of 'eval' in JavaScript`
The Content Security Policy (CSP) prevents the evaluation of arbitrary strings as JavaScript to make it more difficult for an attacker to inject unathorized code on your site.
To solve this issue, avoid using
eval(),new Function(),setTimeout([string], ...)andsetInterval([string], ...)for evaluating strings.If you absolutely must: you can enable string evaluation by adding
unsafe-evalas an allowed source in ascript-srcdirective.⚠️ Allowing string evaluation comes at the risk of inline script injection.
- AFFECTED RESOURCES
- 1 directive
-
Source Location Directive Status report:14743 script-src blocked
Ask
Is there a way to provide plotly.py the ability to use the plotly.js strict bundle and hence avoid having to use dependencies that violate CSP?
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Direção de pesquisa
Comece pelo renderizador de notebook configurado por meio de pio.renderers.default = "notebook" e acompanhe como ele produz o HTML exportado. Compare as dependências incorporadas do plotly.js com o bundle estrito do plotly.js referenciado na issue. Considera-se concluído quando a exportação do notebook funciona sob a política script-src indicada sem exigir unsafe-eval.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- javascript, node.js, python
- Domínio
- data-visualization, frontend, security
- Tipo de issue
- Funcionalidade
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Status de atividade
- Estagnada
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 32/100