feat(csp): infrastructure de sortie de unsafe-inline, et couche partagee migree
SEC-WEB-001 / OPS-010. script-src porte toujours 'unsafe-inline' : c'est
pour cela que le XSS stocke de SEC-XSS-001 s'executait au lieu d'etre
bloque. Le retirer n'est pas un changement d'une ligne.
Ce qui bloque reellement
Un nonce autorise des elements <script> ; il ne peut rien pour un
attribut onclick="...". Mesure faite : 76 gestionnaires en ligne repartis
dans 15 gabarits. Tant qu'il en reste un, la politique ne peut pas etre
durcie.
Piege supplementaire, documente dans build_csp() : en CSP niveau 3, un
navigateur ignore 'unsafe-inline' des qu'un nonce est present. Emettre
les deux ne serait donc pas une transition douce -- ce serait couper
d'un coup tous les scripts en ligne et tous les onclick, et uniquement
sur les navigateurs recents. La bascule doit etre atomique, d'ou un
drapeau unique : CSP_ALLOW_INLINE_SCRIPT.
Infrastructure posee
build_csp() assemble l'en-tete selon le drapeau. Un nonce est genere par
requete et n'est emis que lorsque l'inline est interdit. Les 15 blocs
<script> portent deja nonce="{{ csp_nonce }}", inerte aujourd'hui : la
bascule finale sera un changement de configuration, pas de gabarits.
Couche partagee migree en premier
base.html et macros.html sont rendus sur absolument toutes les pages. Six
gestionnaires retires, remplaces par des attributs data-action et un
ecouteur delegue unique dans main.js. La delegation plutot qu'un
ecouteur par widget : le contenu injecte dynamiquement herite du
comportement sans re-attachement.
Un cliquet plutot qu'une promesse
tests/test_csp.py fixe un budget par gabarit qui ne peut que baisser.
Ajouter un gestionnaire en ligne fait echouer la suite ; en retirer sans
mettre le budget a jour aussi, ce qui force a enregistrer la progression
dans le diff. A zero, il ne reste qu'a basculer le drapeau.
Le cliquet a d'ailleurs corrige mon propre relevé : mon grep initial
comptait 83 gestionnaires, la mesure exacte en donne 76 -- le motif ne
verifiait pas l'espace avant l'attribut.
style-src conserve 'unsafe-inline' : les attributs style="" sont partout et
ne constituent pas un vecteur XSS a eux seuls. Migration distincte.
192 tests.
Co-Authored-By: Claude Opus 5 <[email protected]>
This commit is contained in:
@@ -0,0 +1,156 @@
|
||||
"""Content Security Policy, and the migration away from 'unsafe-inline'.
|
||||
|
||||
SEC-WEB-001 / OPS-010. script-src still carries 'unsafe-inline', which is
|
||||
why the stored XSS of SEC-XSS-001 executed instead of being blocked.
|
||||
|
||||
Removing it is not a one-line change. A nonce authorises `<script>`
|
||||
elements; it can do nothing for `onclick="..."` attributes, and there are
|
||||
dozens of those across the templates. Under CSP level 3 a browser also
|
||||
ignores 'unsafe-inline' the moment a nonce appears, so the two cannot
|
||||
coexist as a gradual transition — the switch is atomic.
|
||||
|
||||
The counts below are a ratchet: they may only go down. Migrating a
|
||||
template and lowering the number is a deliberate act, recorded in the
|
||||
diff. Adding a new inline handler turns the suite red.
|
||||
"""
|
||||
|
||||
import os
|
||||
import re
|
||||
|
||||
import pytest
|
||||
|
||||
from app.app import build_csp
|
||||
|
||||
TEMPLATE_ROOT = os.path.join(
|
||||
os.path.dirname(os.path.dirname(os.path.abspath(__file__))),
|
||||
'app', 'templates',
|
||||
)
|
||||
|
||||
#: Attributes a nonce can never authorise.
|
||||
INLINE_HANDLER = re.compile(
|
||||
r'\son(?:click|change|submit|input|load|keyup|keydown|mouseover|focus|blur)\s*=',
|
||||
re.I,
|
||||
)
|
||||
|
||||
#: Remaining inline handlers, per template. Lower these as you migrate;
|
||||
#: never raise one. Templates absent from this map must have none.
|
||||
HANDLER_BUDGET = {
|
||||
'pages/match_form.html': 13,
|
||||
'pages/calendar.html': 11,
|
||||
'pages/teams.html': 11,
|
||||
'pages/evaluate_player.html': 9,
|
||||
'pages/view_tryout.html': 8,
|
||||
'pages/contracts.html': 4,
|
||||
'pages/notes.html': 4,
|
||||
'pages/team_matches.html': 4,
|
||||
'pages/coach_availability.html': 3,
|
||||
'pages/profile.html': 3,
|
||||
'pages/one_on_one.html': 2,
|
||||
'pages/my_teams.html': 1,
|
||||
'pages/register.html': 1,
|
||||
'pages/users.html': 1,
|
||||
'pages/view_user.html': 1,
|
||||
}
|
||||
|
||||
#: What the ratchet is counting down to.
|
||||
TOTAL_BUDGET = sum(HANDLER_BUDGET.values())
|
||||
|
||||
|
||||
def _templates():
|
||||
for root, _dirs, files in os.walk(TEMPLATE_ROOT):
|
||||
for name in files:
|
||||
if name.endswith('.html'):
|
||||
full = os.path.join(root, name)
|
||||
rel = os.path.relpath(full, TEMPLATE_ROOT).replace(os.sep, '/')
|
||||
yield rel, full
|
||||
|
||||
|
||||
def _count_handlers(path):
|
||||
with open(path, encoding='utf-8') as handle:
|
||||
return len(INLINE_HANDLER.findall(handle.read()))
|
||||
|
||||
|
||||
class TestPolicyHeader:
|
||||
def test_the_current_policy_still_allows_inline_script(self, client):
|
||||
"""Documents where we are, not where we want to be."""
|
||||
csp = client.get('/auth/login').headers['Content-Security-Policy']
|
||||
assert "'unsafe-inline'" in csp
|
||||
|
||||
def test_the_policy_pins_the_dangerous_directives(self, client):
|
||||
csp = client.get('/auth/login').headers['Content-Security-Policy']
|
||||
|
||||
assert "default-src 'self'" in csp
|
||||
assert "frame-ancestors 'none'" in csp
|
||||
assert "base-uri 'self'" in csp
|
||||
assert "form-action 'self'" in csp
|
||||
assert "object-src" not in csp or "object-src 'none'" in csp
|
||||
|
||||
def test_no_nonce_is_emitted_while_inline_script_is_allowed(self, client):
|
||||
"""Emitting both would silently drop every inline script in modern
|
||||
browsers, since a nonce makes them ignore 'unsafe-inline'."""
|
||||
csp = client.get('/auth/login').headers['Content-Security-Policy']
|
||||
assert 'nonce-' not in csp
|
||||
|
||||
def test_the_hardened_policy_carries_a_nonce_and_no_unsafe_inline(self):
|
||||
csp = build_csp(allow_inline_script=False, nonce='abc123')
|
||||
|
||||
assert "'nonce-abc123'" in csp
|
||||
assert "'unsafe-inline'" not in csp.split('style-src')[0]
|
||||
|
||||
def test_each_request_gets_a_distinct_nonce(self, app):
|
||||
"""A reused nonce is worth no more than 'unsafe-inline'."""
|
||||
application = app
|
||||
application.config['CSP_ALLOW_INLINE_SCRIPT'] = False
|
||||
client = application.test_client()
|
||||
|
||||
seen = set()
|
||||
for _ in range(5):
|
||||
csp = client.get('/auth/login').headers['Content-Security-Policy']
|
||||
seen.add(re.search(r"'nonce-([^']+)'", csp).group(1))
|
||||
|
||||
assert len(seen) == 5
|
||||
|
||||
|
||||
class TestInlineHandlerRatchet:
|
||||
@pytest.mark.parametrize('relative,full', list(_templates()))
|
||||
def test_a_template_never_gains_an_inline_handler(self, relative, full):
|
||||
allowed = HANDLER_BUDGET.get(relative, 0)
|
||||
found = _count_handlers(full)
|
||||
|
||||
assert found <= allowed, (
|
||||
f'{relative} has {found} inline event handler(s), budget is '
|
||||
f'{allowed}. A nonce cannot authorise these — use '
|
||||
f'data-action="..." and the delegated listener in main.js.'
|
||||
)
|
||||
|
||||
def test_the_budget_map_has_no_stale_entries(self):
|
||||
"""Lower an entry to zero and it must be deleted, so the map keeps
|
||||
reflecting the real remaining work."""
|
||||
actual = {rel: _count_handlers(full) for rel, full in _templates()}
|
||||
|
||||
stale = [rel for rel, allowed in HANDLER_BUDGET.items()
|
||||
if actual.get(rel, 0) < allowed]
|
||||
|
||||
assert not stale, (
|
||||
f'Budget is now higher than reality for {stale}. Lower or remove '
|
||||
f'these entries so the count keeps meaning something.'
|
||||
)
|
||||
|
||||
def test_the_shared_layout_is_already_free_of_them(self):
|
||||
"""base.html and macros.html render on every single page, so they
|
||||
were migrated first."""
|
||||
for relative in ('layouts/base.html', 'layouts/macros.html'):
|
||||
full = os.path.join(TEMPLATE_ROOT, *relative.split('/'))
|
||||
assert _count_handlers(full) == 0, f'{relative} regressed'
|
||||
|
||||
def test_progress_is_recorded(self):
|
||||
"""Fails when the total drops, as a reminder to update the budget
|
||||
and, once it reaches zero, to flip CSP_ALLOW_INLINE_SCRIPT."""
|
||||
total = sum(_count_handlers(full) for _rel, full in _templates())
|
||||
|
||||
assert total <= TOTAL_BUDGET
|
||||
assert total == TOTAL_BUDGET, (
|
||||
f'{TOTAL_BUDGET - total} handler(s) removed since the budget was '
|
||||
f'last updated — lower HANDLER_BUDGET to {total}. At zero, set '
|
||||
f'CSP_ALLOW_INLINE_SCRIPT to false and delete this ratchet.'
|
||||
)
|
||||
Reference in New Issue
Block a user