diff --git a/.jules/sentinel.md b/.jules/sentinel.md index 4f173bc..22e09ba 100644 --- a/.jules/sentinel.md +++ b/.jules/sentinel.md @@ -38,3 +38,7 @@ **Vulnerability:** Missing input validation on `setLanguage()` could allow invalid strings (like Prototype Pollution payloads or arbitrary text) to be applied to the DOM (`lang` attribute) and stored in `localStorage`. **Learning:** The global `setLanguage` function assumed inputs would only come from predefined button clicks, skipping runtime validation. **Prevention:** Always sanitize and validate function arguments at the application boundary, even if the primary caller is trusted, to enforce defense in depth. +## 2026-08-02 - CSP `base-uri` 강화 +**Vulnerability:** `base-uri 'self'` 설정은 정적 사이트에서 불필요하게 `self` 출처의 base 태그 주입을 허용할 여지를 남깁니다. +**Learning:** 애플리케이션에서 동적으로 경로를 해석할 때 기준(base) URL을 악의적으로 변경하여 리소스를 가로채는 Base Tag Injection 공격 위험을 줄이려면, `` 태그를 전혀 사용하지 않는 환경의 경우 가장 강력한 `base-uri 'none'`을 적용해야 합니다. +**Prevention:** `` 태그가 명시적으로 필요하지 않은 모든 정적 웹 애플리케이션의 CSP 설정 시 `base-uri 'none'`을 기본으로 적용하여 공격 표면을 최소화합니다. diff --git a/CHANGELOG.md b/CHANGELOG.md index 56ad628..69306e0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,7 @@ # CHANGELOG ## [Unreleased] +- **보안 개선**: `index.html`의 CSP 정책에서 `base-uri`를 `'none'`으로 강화하여 Base Tag Injection 취약점을 원천 차단했습니다. - **보안 개선**: 컴포넌트 갤러리의 인라인 스크립트와 스타일을 외부 파일로 분리하고, 엄격한 Content-Security-Policy를 적용해 XSS 방어를 강화했습니다. - **성능 회귀 복원**: 오프스크린 `.section` 렌더링을 `content-visibility: auto`로 지연하고, 일반 섹션은 600px·콘텐츠가 큰 DIKW/projects 섹션은 1000px의 `contain-intrinsic-size` placeholder를 유지해 초기 렌더링 비용과 스크롤바 이동을 함께 줄였습니다. - **보안 개선**: Trusted Types 기반 CSP 강화: 잠재적인 DOM 기반 XSS 공격을 방지하기 위해 `require-trusted-types-for 'script'` 지시어 추가 diff --git a/index.html b/index.html index c40fea3..25ee55a 100644 --- a/index.html +++ b/index.html @@ -3,7 +3,7 @@ - + 맥락지혜 연구실 | Contextual Wisdom Lab None: + """The main index page limits active content to same-origin assets.""" + html = INDEX.read_text(encoding="utf-8") + match = re.search( + r'