Repository navigation
fix(security): name font-src in the meta CSP so a font cannot load off-origin - #1284
Merged
Merged
Conversation
…f-origin The meta Content-Security-Policy ships no default-src, so every fetch directive it does not name is unrestricted rather than inheriting a fallback. font-src was the last one still unnamed: the browser would fetch a font from any host, and style-src carries 'unsafe-inline', so an inline @font-face that reached a page could name one. A font fetch discloses the visitor's IP, User-Agent and Referer to that host. The directive was left out only because nothing in the build asserted the premise that the site loads no remote font. It does now: the new CSS scan fails if any url() in a shipped stylesheet resolves off-origin, judged by remoteTarget() -- the same classifier the SVG and MDX gates ask, so a protocol-relative or backslash-prefixed authority is treated here exactly as it is there. The site's fonts are vendored in static/fonts and named by root-relative url(), so 'self' constrains nothing the site actually does. Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will keep the |
This was referenced Oct 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
Claims exactly two files: the CSP directive list in
docusaurus.config.jsandthe CSP assertions in
tests/site-config.test.mjs. Touches no gate module, novalidator and no importer, so it is disjoint from every other open PR.
The meta Content-Security-Policy ships no
default-src, so every fetchdirective it does not name is unrestricted rather than inheriting a fallback —
the config's own comment says so.
font-srcwas the last fetch directive stillunnamed, so the browser would fetch a font from any host.
style-srccarries'unsafe-inline'(Docusaurus emits inline styles), so an inline@font-facethat reached a page could name one, disclosing every visitor's IP address,
User-Agent and Referer to that host.
This is the same asymmetry
frame-src,media-srcandconnect-srcwereadded to close, on the same defence-in-depth footing: a backstop for the case
where a gate is bypassed, regresses, or a page is added without one. No current
bypass is known, so this is hardening, not an exploitable fix.
Why it could be set now
The directive was omitted only because nothing in the build asserted the
premise — the comment said so explicitly: "the site loads no remote font, but
nothing in the build asserts that, so the directive is left for a change that
can verify it." This change supplies that assertion.
no shipped stylesheet names an off-origin font or other remote resourcewalksevery
.cssundersrc/and fails if anyurl()resolves off-origin, judgedby
remoteTarget()fromscripts/lib/uri-safety.mjs— the same classifier theSVG and MDX gates ask, so a protocol-relative or backslash-prefixed authority is
treated here exactly as it is there. The fonts themselves are vendored in
static/fonts/and named by root-relativeurl('/fonts/ClarityCity-*.woff2'),so
'self'constrains nothing the site actually does.Verification
node --test tests/site-config.test.mjs: 28 pass, 0 fail.font-srcline makes the new directive assertion fail(
fail 1), so it pins the directive rather than passing vacuously.NODE_ENV=production npx docusaurus buildsucceeds, and the emittedindex.htmlcarries...; connect-src 'self'; font-src 'self'; form-action 'self'; ....url()inassets/css/*.cssis same-origin ordata:(zero matched neither), and every
@font-facesrcis/assets/fonts/<file>,so nothing the site ships is blocked by the new directive.
prettier --checkandeslintclean on both changed files.Refs #1254 (the rest of that issue stays open: its primary subject is the MDX
remote-image gate in
scripts/lib/mdx-active-content.mjs, which PR #1255already covers; this PR deliberately changes no gate module. The CSP finding was
folded into #1254 by the hive's filename heuristic, not because the two share a
fix.)
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88