From 228ff32d385628250dc454b59a7d5f6d7f3cd922 Mon Sep 17 00:00:00 2001
From: seonghobae <8172694+seonghobae@users.noreply.github.com>
Date: Wed, 29 Jul 2026 14:03:33 +0000
Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Sentinel:=20[=EB=B3=B4?=
=?UTF-8?q?=EC=95=88=20=EA=B0=9C=EC=84=A0]=20Prevent=20base=20tag=20inject?=
=?UTF-8?q?ion=20by=20enforcing=20base-uri=20'none'?=
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
이 커밋은 정적 사이트의 index.html Content-Security-Policy에서 `base-uri 'self'`를 `base-uri 'none'`으로 강화하여, 악의적인 베이스 태그 주입(Base Tag Injection) 공격의 가능성을 원천 차단합니다. 변경 사항을 검증하는 테스트 케이스를 추가하고, 관련 지식을 저널에 기록했습니다.
---
.jules/sentinel.md | 4 ++++
CHANGELOG.md | 1 +
index.html | 2 +-
tests/test_index_security.py | 26 ++++++++++++++++++++++++++
4 files changed, 32 insertions(+), 1 deletion(-)
create mode 100644 tests/test_index_security.py
diff --git a/.jules/sentinel.md b/.jules/sentinel.md
index 4f173bc..c07cc17 100644
--- a/.jules/sentinel.md
+++ b/.jules/sentinel.md
@@ -38,3 +38,7 @@
**Vulnerability:** Missing input validation on `setLanguage()` could allow invalid strings (like Prototype Pollution payloads or arbitrary text) to be applied to the DOM (`lang` attribute) and stored in `localStorage`.
**Learning:** The global `setLanguage` function assumed inputs would only come from predefined button clicks, skipping runtime validation.
**Prevention:** Always sanitize and validate function arguments at the application boundary, even if the primary caller is trusted, to enforce defense in depth.
+## 2026-07-29 - Prevent Base Tag Injection via CSP
+**Vulnerability:** The Content-Security-Policy in `index.html` used `base-uri 'self'`, which, while somewhat restrictive, could still allow attackers to inject a `