Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,3 +38,7 @@
**Vulnerability:** Missing input validation on `setLanguage()` could allow invalid strings (like Prototype Pollution payloads or arbitrary text) to be applied to the DOM (`lang` attribute) and stored in `localStorage`.
**Learning:** The global `setLanguage` function assumed inputs would only come from predefined button clicks, skipping runtime validation.
**Prevention:** Always sanitize and validate function arguments at the application boundary, even if the primary caller is trusted, to enforce defense in depth.
## 2026-07-29 - Prevent Base Tag Injection via CSP
**Vulnerability:** The Content-Security-Policy in `index.html` used `base-uri 'self'`, which, while somewhat restrictive, could still allow attackers to inject a `<base>` tag pointing to a malicious path on the same origin (if one existed or could be created) or could be unnecessarily loose for a static site that does not use `<base>`.
**Learning:** For static sites that do not explicitly require a `<base>` tag for relative URL resolution, using `base-uri 'self'` is overly permissive. Base tag injection can hijack relative links and form submissions.
**Prevention:** When configuring Content Security Policy (CSP) for static sites that do not explicitly require a `<base>` tag, use `base-uri 'none'` instead of `base-uri 'self'` to strictly prevent base tag injection attacks.
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# CHANGELOG

## [Unreleased]
- **보안 개선**: 정적 사이트의 Base Tag Injection 공격을 예방하기 위해 `index.html`의 Content-Security-Policy에서 `base-uri 'self'`를 `base-uri 'none'`으로 강화했습니다.
- **보안 개선**: 컴포넌트 갤러리의 인라인 스크립트와 스타일을 외부 파일로 분리하고, 엄격한 Content-Security-Policy를 적용해 XSS 방어를 강화했습니다.
- **성능 회귀 복원**: 오프스크린 `.section` 렌더링을 `content-visibility: auto`로 지연하고, 일반 섹션은 600px·콘텐츠가 큰 DIKW/projects 섹션은 1000px의 `contain-intrinsic-size` placeholder를 유지해 초기 렌더링 비용과 스크롤바 이동을 함께 줄였습니다.
- **보안 개선**: Trusted Types 기반 CSP 강화: 잠재적인 DOM 기반 XSS 공격을 방지하기 위해 `require-trusted-types-for 'script'` 지시어 추가
Expand Down
2 changes: 1 addition & 1 deletion index.html
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; img-src 'self'; object-src 'none'; base-uri 'self'; form-action 'none'; upgrade-insecure-requests; require-trusted-types-for 'script';">
<meta http-equiv="Content-Security-Policy" content="default-src 'self'; img-src 'self'; object-src 'none'; base-uri 'none'; form-action 'none'; upgrade-insecure-requests; require-trusted-types-for 'script';">
<meta name="referrer" content="strict-origin-when-cross-origin">
<title>맥락지혜 연구실 | Contextual Wisdom Lab</title>
<meta
Expand Down
26 changes: 26 additions & 0 deletions tests/test_index_security.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
"""Security tests for the main site index.html."""

import re
from pathlib import Path

ROOT = Path(__file__).resolve().parents[1]
INDEX = ROOT / "index.html"

def _index_html() -> str:
"""Return the main index HTML source."""
return INDEX.read_text(encoding="utf-8")

def _csp_content(html: str) -> str:
"""Extract the CSP meta policy from the HTML."""
match = re.search(
r'<meta\s+http-equiv="Content-Security-Policy"\s+content="([^"]+)"',
html,
)
assert match is not None, "index.html must declare a CSP meta policy"
return match.group(1)

def test_index_declares_base_uri_none() -> None:
"""The main site prevents base tag injection attacks."""
policy = _csp_content(_index_html())
assert "base-uri 'none'" in policy
assert "base-uri 'self'" not in policy
Loading