Skip to content

πŸ›‘οΈ Sentinel: [MEDIUM] Fix CSP Hash Mismatch due to Kotlin Multiline Strings - #283

Closed
seonghobae wants to merge 1 commit into
masterfrom
sentinel-csp-hash-fix-10525982417683885382
Closed

πŸ›‘οΈ Sentinel: [MEDIUM] Fix CSP Hash Mismatch due to Kotlin Multiline Strings#283
seonghobae wants to merge 1 commit into
masterfrom
sentinel-csp-hash-fix-10525982417683885382

Conversation

@seonghobae

@seonghobae seonghobae commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

🚨 Severity: MEDIUM
πŸ’‘ Vulnerability: Kotlin 닀쀑 쀄 λ¬Έμžμ—΄μ˜ 곡백 및 λ“€μ—¬μ“°κΈ° λ•Œλ¬Έμ— κ³„μ‚°λœ CSP ν•΄μ‹œμ™€ μ‹€μ œ μ£Όμž…λœ <style> λ‚΄μš©μ˜ ν•΄μ‹œκ°€ μΌμΉ˜ν•˜μ§€ μ•Šμ•„ λ³΄μ•ˆ 정책이 μ˜¬λ°”λ₯΄κ²Œ μ μš©λ˜μ§€ μ•ŠλŠ” λ¬Έμ œκ°€ μžˆμ—ˆμŠ΅λ‹ˆλ‹€.
🎯 Impact: λΈŒλΌμš°μ €μ—μ„œ 인라인 μŠ€νƒ€μΌμ΄ CSP에 μ˜ν•΄ μ°¨λ‹¨λ˜κ±°λ‚˜, λΆ€μ •ν™•ν•œ ν•΄μ‹œλ‘œ 인해 λ³΄μ•ˆ μ •μ±… 검증이 μ‹€νŒ¨ν•  수 μžˆμŠ΅λ‹ˆλ‹€.
πŸ”§ Fix: cssContent, styleHash, css 선언을 μ΅œμƒμœ„ private val μƒμˆ˜λ‘œ μ΄λ™ν•˜κ³  .trimIndent()λ₯Ό μ‚¬μš©ν•˜μ—¬ 곡백을 제거, <style> νƒœκ·Έμ— μ—¬λ°± 없이 λ‚΄μš©μ„ μ‚½μž…ν•˜λ„λ‘ μˆ˜μ •ν–ˆμŠ΅λ‹ˆλ‹€.
βœ… Verification: export JAVA_HOME=/usr/lib/jvm/java-8-openjdk-amd64 && ./gradlew clean test jacocoTestReport jacocoTestCoverageVerification --continue λͺ…령을 톡해 100% ν…ŒμŠ€νŠΈ 컀버리지λ₯Ό κ²€μ¦ν–ˆμŠ΅λ‹ˆλ‹€.


PR created automatically by Jules for task 10525982417683885382 started by @seonghobae

Summary by CodeRabbit

  • 버그 μˆ˜μ •

    • 인라인 μŠ€νƒ€μΌμ˜ λ³΄μ•ˆ μ •μ±… ν•΄μ‹œκ°€ μ‹€μ œ λΈŒλΌμš°μ € μ½˜ν…μΈ μ™€ μ •ν™•νžˆ μΌμΉ˜ν•˜λ„λ‘ κ°œμ„ ν–ˆμŠ΅λ‹ˆλ‹€.
    • νŽ˜μ΄μ§€ 생성 μ‹œ λΆˆν•„μš”ν•œ κ³΅λ°±μ΄λ‚˜ μ€„λ°”κΏˆμœΌλ‘œ 인해 μŠ€νƒ€μΌμ΄ μ μš©λ˜μ§€ μ•Šλ˜ 문제λ₯Ό λ°©μ§€ν–ˆμŠ΅λ‹ˆλ‹€.
  • λ³΄μ•ˆ

    • μ½˜ν…μΈ  λ³΄μ•ˆ μ •μ±…(CSP) 적용 일관성을 κ°•ν™”ν•΄ μŠ€νƒ€μΌ 차단 및 κ΄€λ ¨ λ³΄μ•ˆ μœ„ν—˜μ„ μ€„μ˜€μŠ΅λ‹ˆλ‹€.
    • μƒμ„±λ˜λŠ” νŽ˜μ΄μ§€ μ „λ°˜μ—μ„œ λ™μΌν•œ μŠ€νƒ€μΌ λ³΄μ•ˆ 검증이 μ μš©λ©λ‹ˆλ‹€.

Copilot AI review requested due to automatic review settings July 27, 2026 03:30
@google-labs-jules

Copy link
Copy Markdown

πŸ‘‹ Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a πŸ‘€ emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@coderabbitai

coderabbitai Bot commented Jul 27, 2026

Copy link
Copy Markdown

Review Change Stack

πŸ“ Walkthrough

Walkthrough

CSS μ½˜ν…μΈ μ™€ CSP μŠ€νƒ€μΌ ν•΄μ‹œ 생성을 μ „μ—­ κ°’μœΌλ‘œ μ€‘μ•™ν™”ν•˜κ³ , 디렉터리별 HTML μƒμ„±μ—μ„œ 이λ₯Ό μž¬μ‚¬μš©ν•˜λ„λ‘ λ³€κ²½ν–ˆμŠ΅λ‹ˆλ‹€. Kotlin 닀쀑 쀄 λ¬Έμžμ—΄μ˜ CSP ν•΄μ‹œ 뢈일치 예방 지침도 λ³΄μ•ˆ λ¬Έμ„œμ— μΆ”κ°€ν–ˆμŠ΅λ‹ˆλ‹€.

Changes

CSP μŠ€νƒ€μΌ ν•΄μ‹œ 쀑앙화

Layer / File(s) Summary
μŠ€νƒ€μΌ μ½˜ν…μΈ μ™€ CSP ν•΄μ‹œ 쀑앙화
src/main/kotlin/html4tree/main.kt, .jules/sentinel.md
CSS 원문, SHA-256 기반 styleHash, <style> 래퍼λ₯Ό 파일 μƒλ‹¨μ—μ„œ μƒμ„±ν•˜κ³  process_dir의 CSP 및 HTML μŠ€νƒ€μΌ μ‚½μž…μ—μ„œ μž¬μ‚¬μš©ν•©λ‹ˆλ‹€. λ³΄μ•ˆ λ¬Έμ„œμ—λŠ” trimIndent()와 μ •ν™•ν•œ μŠ€νƒ€μΌ μ½˜ν…μΈ  μ£Όμž… 지침이 μΆ”κ°€λ˜μ—ˆμŠ΅λ‹ˆλ‹€.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: copilot

πŸš₯ Pre-merge checks | βœ… 5
βœ… Passed checks (5 passed)
Check name Status Explanation
Description Check βœ… Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check βœ… Passed 제λͺ©μ΄ Kotlin multiline λ¬Έμžμ—΄λ‘œ μΈν•œ CSP ν•΄μ‹œ 뢈일치 μˆ˜μ •μ΄λΌλŠ” 핡심 변경을 μ •ν™•νžˆ μš”μ•½ν•©λ‹ˆλ‹€.
Docstring Coverage βœ… Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check βœ… Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check βœ… Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
πŸ“ Generate docstrings
  • Create stacked PR
  • Commit on current branch
πŸ§ͺ Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sentinel-csp-hash-fix-10525982417683885382

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses a CSP (Content-Security-Policy) style hash mismatch caused by whitespace/indentation artifacts from Kotlin multiline strings, ensuring the computed sha256-... hash matches the exact <style> contents injected into generated index.html files.

Changes:

  • Moves the inline CSS, its SHA-256 hash computation, and the rendered <style> block to top-level private vals so the content is stable and reused.
  • Applies .trimIndent() to normalize multiline CSS formatting and removes extra whitespace inside the <style> element that previously broke hash validation.
  • Adds a new Sentinel learning entry documenting the issue and prevention guidance.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
src/main/kotlin/html4tree/main.kt Normalizes CSS multiline string formatting and centralizes CSS + CSP hash generation to prevent CSP hash mismatches.
.jules/sentinel.md Documents the CSP hash mismatch root cause and prevention guidance for future hardening.

πŸ’‘ Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (1)
src/main/kotlin/html4tree/main.kt (1)

97-101: πŸ”’ Security & Privacy | πŸ”΅ Trivial | ⚑ Quick win

μ‹€μ œ <style> λ³Έλ¬Έκ³Ό ν•΄μ‹œμ˜ 일치λ₯Ό νšŒκ·€ ν…ŒμŠ€νŠΈλ‘œ κ²€μ¦ν•˜μ„Έμš”.

ν˜„μž¬ MainTest.kt:305-346은 CSP ν•΄μ‹œμ˜ ν˜•μ‹κ³Ό CSS 쑰각만 ν™•μΈν•©λ‹ˆλ‹€. cssContent와 μ‹€μ œ μ‚½μž…λœ <style> 본문이 달라도 ν…ŒμŠ€νŠΈκ°€ 톡과할 수 μžˆμœΌλ―€λ‘œ, μƒμ„±λœ μŠ€νƒ€μΌ 본문을 μΆ”μΆœν•΄ SHA-256/Base64λ₯Ό κ³„μ‚°ν•œ λ’€ CSP의 ν•΄μ‹œμ™€ λΉ„κ΅ν•˜λŠ” 검증을 μΆ”κ°€ν•˜μ„Έμš”.

πŸ€– Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/main/kotlin/html4tree/main.kt` around lines 97 - 101, Update the
regression tests around the CSP hash checks in MainTest.kt to extract the
generated `<style>` element’s actual body, compute its SHA-256 digest and Base64
value, and assert it matches the CSP hash. Keep the existing hash-format and
CSS-fragment assertions, and anchor the new validation to the generated style
output rather than only cssContent.
πŸ€– Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.jules/sentinel.md:
- Around line 87-90: Update the CSP guidance in the html4tree entry to state
that hash mismatches typically cause browsers to block styles, not enable a
policy bypass. Revise the existing nonce-based guidance around the referenced
security instructions to match the current hash-based implementation, or
explicitly mark it as historical.

---

Nitpick comments:
In `@src/main/kotlin/html4tree/main.kt`:
- Around line 97-101: Update the regression tests around the CSP hash checks in
MainTest.kt to extract the generated `<style>` element’s actual body, compute
its SHA-256 digest and Base64 value, and assert it matches the CSP hash. Keep
the existing hash-format and CSS-fragment assertions, and anchor the new
validation to the generated style output rather than only cssContent.
πŸͺ„ Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
βš™οΈ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4f41bc2e-f37c-4395-9389-c92d002d222c

πŸ“₯ Commits

Reviewing files that changed from the base of the PR and between a859a11 and 00d89f9.

πŸ“’ Files selected for processing (2)
  • .jules/sentinel.md
  • src/main/kotlin/html4tree/main.kt

Comment thread .jules/sentinel.md
Comment on lines +87 to +90
## 2026-07-27 - [html4tree] CSP Hash Mismatch due to Kotlin Multiline Strings
**Vulnerability:** λΈŒλΌμš°μ €κ°€ CSP(Content-Security-Policy) ν•΄μ‹œλ₯Ό 계산할 λ•Œ, 인라인 μŠ€ν¬λ¦½νŠΈμ™€ μŠ€νƒ€μΌμ˜ μ •ν™•ν•œ ν…μŠ€νŠΈμ— κΈ°λ°˜ν•©λ‹ˆλ‹€. Kotlin의 닀쀑 쀄 λ¬Έμžμ—΄ λ‚΄μ˜ λΆˆν•„μš”ν•œ 곡백과 μ€„λ°”κΏˆμœΌλ‘œ 인해 μƒμ„±λœ ν•΄μ‹œμ™€ λΈŒλΌμš°μ €κ°€ κ³„μ‚°ν•œ ν•΄μ‹œκ°€ λΆˆμΌμΉ˜ν•˜μ—¬, 결과적으둜 μŠ€νƒ€μΌ 적용이 μ‹€νŒ¨ν•˜κ±°λ‚˜ λ³΄μ•ˆ μ •μ±… 우회 κ°€λŠ₯성이 μƒκΉλ‹ˆλ‹€.
**Learning:** 정적 생성 λ„κ΅¬μ—μ„œ CSPλ₯Ό μœ„ν•΄ μ½˜ν…μΈ  ν•΄μ‹œλ₯Ό 계산할 λ•ŒλŠ”, 인젝트된 μ½˜ν…μΈ  μ£Όλ³€μ˜ 암묡적 μ—¬λ°±μ΄λ‚˜ λ“€μ—¬μ“°κΈ°κ°€ κ²°κ³Ό ν•΄μ‹œλ₯Ό λ¬΄νš¨ν™”ν•  수 μžˆμŒμ„ 인지해야 ν•©λ‹ˆλ‹€.
**Prevention:** μ½˜ν…μΈ  λ¬Έμžμ—΄μ— `.trimIndent()`λ₯Ό μ μš©ν•˜μ—¬ ν•΄μ‹± 전에 포맷을 μ •λ¦¬ν•˜κ³ , 암묡적 μ—¬λ°± 없이(예: `<style>${exactStyleContent}</style>`) HTML에 μΈμ νŠΈν•˜μ—¬ μ™„μ „ν•œ ν•΄μ‹œ 일치λ₯Ό 보μž₯ν•˜μ‹­μ‹œμ˜€.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ”’ Security & Privacy | 🟑 Minor | ⚑ Quick win

CSP 뢈일치의 영ν–₯κ³Ό κΈ°μ‘΄ nonce 지침을 μ •μ •ν•˜μ„Έμš”.

ν•΄μ‹œ λΆˆμΌμΉ˜λŠ” 일반적으둜 λΈŒλΌμš°μ €κ°€ μŠ€νƒ€μΌμ„ μ°¨λ‹¨ν•˜λŠ” λ¬Έμ œμ΄μ§€, λ³΄μ•ˆ μ •μ±… 우회λ₯Ό κ°€λŠ₯ν•˜κ²Œ ν•˜λŠ” λ¬Έμ œλŠ” μ•„λ‹™λ‹ˆλ‹€. λ˜ν•œ 24ν–‰μ˜ nonce 기반 지침이 ν˜„μž¬μ˜ hash 기반 κ΅¬ν˜„κ³Ό μΆ©λŒν•˜λ―€λ‘œ, κΈ°μ‘΄ ν•­λͺ©μ„ hash λ°©μ‹μœΌλ‘œ κ°±μ‹ ν•˜κ±°λ‚˜ 역사적 μ§€μΉ¨μž„μ„ λͺ…ν™•νžˆ ν‘œμ‹œν•˜μ„Έμš”.

πŸ€– Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.jules/sentinel.md around lines 87 - 90, Update the CSP guidance in the
html4tree entry to state that hash mismatches typically cause browsers to block
styles, not enable a policy bypass. Revise the existing nonce-based guidance
around the referenced security instructions to match the current hash-based
implementation, or explicitly mark it as historical.

Copy link
Copy Markdown
Collaborator Author

Closing as superseded by canonical #363. Both normalize the multiline stylesheet and inject it without template padding, but #363 additionally proves byte identity through an independent real generated-file digest oracle, adds one-time hashing, APA 7 doctoring, changelog, and fresh current-head CI/JaCoCo/security evidence. No result from this duplicate head is reused.

@seonghobae seonghobae closed this Aug 5, 2026
@google-labs-jules

Copy link
Copy Markdown

Closing as superseded by canonical #363. Both normalize the multiline stylesheet and inject it without template padding, but #363 additionally proves byte identity through an independent real generated-file digest oracle, adds one-time hashing, APA 7 doctoring, changelog, and fresh current-head CI/JaCoCo/security evidence. No result from this duplicate head is reused.

Understood. Acknowledging that this work is now obsolete and stopping work on this task.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants