Output of renderer 'notebook' violates Content Security Policy
还没有人认领这个 Issue。
- 主要语言
- Python
- 星标
- 18.8k
- 派生
- 2.8k
- 平均合并
- 16 小时 26 分钟
- 30 天内合并 PR
- 21
描述
Setup description
We have plotly.py setup with pio.renderers.default = "notebook" and we use nbconvert 6.5 to convert executed notebooks to HTML reports with input cells stripped out. These HTMLs are served by a simple node.js front end that has Content Security Policies for script-src setup due to security requirements.
Issue description
The exported HTML contains inline script tags one of which has plotly.js and its dependencies. One of the dependencies seems to violate our script-src Content Security Policy as it is using eval(), new Function(), setTimeout([string], ...) and setInterval([string], ...) for evaluating strings Reference
CSP Error from Chrome:
- Content Security Policy of your site blocks the use of 'eval' in JavaScript`
The Content Security Policy (CSP) prevents the evaluation of arbitrary strings as JavaScript to make it more difficult for an attacker to inject unathorized code on your site.
To solve this issue, avoid using
eval(),new Function(),setTimeout([string], ...)andsetInterval([string], ...)for evaluating strings.If you absolutely must: you can enable string evaluation by adding
unsafe-evalas an allowed source in ascript-srcdirective.⚠️ Allowing string evaluation comes at the risk of inline script injection.
- AFFECTED RESOURCES
- 1 directive
-
Source Location Directive Status report:14743 script-src blocked
Ask
Is there a way to provide plotly.py the ability to use the plotly.js strict bundle and hence avoid having to use dependencies that violate CSP?
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从通过 pio.renderers.default = "notebook" 配置的 notebook renderer 开始,追踪它如何生成导出的 HTML。将嵌入的 plotly.js 依赖项与 issue 中引用的 plotly.js strict bundle 进行比较。在所述的 script-src 策略下,notebook export 无需 unsafe-eval 即可正常工作,即视为完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- javascript, node.js, python
- 领域
- data-visualization, frontend, security
- Issue 类型
- 功能
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 32/100