fix(app-proxy): make the SPA shell identical for every visitor (#3112)

This commit is contained in:
Hampus
2026-10-02 15:13:36 +02:00
committed by GitHub
parent 1eed347ffb
commit e297a6a653
15 changed files with 578 additions and 220 deletions
Generated
+1
View File
@@ -2040,6 +2040,7 @@ dependencies = [
"reqwest",
"serde",
"serde_json",
"sha2 0.11.0",
"tokio",
"tokio-util",
"tower",
+3 -3
View File
@@ -23,9 +23,9 @@
<meta name="display" content="standalone">
<link rel="license" href="/assets/fonts-NOTICE.txt">
<!--{{FLUXER_BOOTSTRAP}}-->
<script nonce="{{CSP_NONCE_PLACEHOLDER}}">(function(){try{var loc=window.location;if(loc.pathname==='/'){var target='/channels/@me';if(loc.search)target+=loc.search;if(loc.hash)target+=loc.hash;loc.replace(target);}}catch(e){}})();</script>
<script nonce="{{CSP_NONCE_PLACEHOLDER}}">(function(){try{var t=localStorage.getItem('theme');if(t){document.documentElement.classList.add('theme-'+t)}}catch{}})()</script>
<script nonce="{{CSP_NONCE_PLACEHOLDER}}">(function(){try{if(typeof WebSocket!=='function')return;if(window.location.pathname.indexOf('/migrate/')===0)return;var t=localStorage.getItem('token');if(!t||t==='undefined'||t==='null')return;var b=window.__FLUXER_BOOTSTRAP__;var g=b&&b.instance&&b.instance.endpoints&&b.instance.endpoints.gateway;if(!g)return;var u=new URL(g);u.searchParams.set('v','1');u.searchParams.set('encoding','json');u.searchParams.set('compress','zstd-stream');u.searchParams.set('stream','1');var url=u.toString();var ws=new WebSocket(url);ws.binaryType='arraybuffer';var s={open:false,url:url,messages:[],startedAt:Date.now()};ws.onopen=function(){s.open=true};ws.onmessage=function(e){s.messages.push(e)};ws.onclose=ws.onerror=function(){window.__FLUXER_FAST_CONNECT__=null};window.__FLUXER_FAST_CONNECT__={ws:ws,state:s};setTimeout(function(){var h=window.__FLUXER_FAST_CONNECT__;if(h&&h.ws===ws){window.__FLUXER_FAST_CONNECT__=null;try{ws.close(1000,'Fast connect unclaimed')}catch(e){}}},30000)}catch(e){}})()</script>
<script>(function(){try{var loc=window.location;if(loc.pathname==='/'){var target='/channels/@me';if(loc.search)target+=loc.search;if(loc.hash)target+=loc.hash;loc.replace(target);}}catch(e){}})();</script>
<script>(function(){try{var t=localStorage.getItem('theme');if(t){document.documentElement.classList.add('theme-'+t)}}catch{}})()</script>
<script>(function(){try{if(typeof WebSocket!=='function')return;if(window.location.pathname.indexOf('/migrate/')===0)return;var t=localStorage.getItem('token');if(!t||t==='undefined'||t==='null')return;var b=window.__FLUXER_BOOTSTRAP__;var g=b&&b.instance&&b.instance.endpoints&&b.instance.endpoints.gateway;if(!g)return;var u=new URL(g);u.searchParams.set('v','1');u.searchParams.set('encoding','json');u.searchParams.set('compress','zstd-stream');u.searchParams.set('stream','1');var url=u.toString();var ws=new WebSocket(url);ws.binaryType='arraybuffer';var s={open:false,url:url,messages:[],startedAt:Date.now()};ws.onopen=function(){s.open=true};ws.onmessage=function(e){s.messages.push(e)};ws.onclose=ws.onerror=function(){window.__FLUXER_FAST_CONNECT__=null};window.__FLUXER_FAST_CONNECT__={ws:ws,state:s};setTimeout(function(){var h=window.__FLUXER_FAST_CONNECT__;if(h&&h.ws===ws){window.__FLUXER_FAST_CONNECT__=null;try{ws.close(1000,'Fast connect unclaimed')}catch(e){}}},30000)}catch(e){}})()</script>
</head>
<body>
<div id="root"></div>
+1 -1
View File
@@ -160,7 +160,7 @@ async function bootstrapApp(): Promise<void> {
loadLazyModule(() => import('@app/features/auth/state/AccountManager')),
loadLazyModule(() => import('@app/features/channel/state/ChannelDisplayName')),
loadLazyModule(() => import('@app/features/channel/state/ChannelFrecency')),
loadLazyModule(() => import('@app/features/app/state/GeoIP')),
loadLazyModule(() => import('@app/features/app/state/GeoIP')).then(({default: GeoIP}) => GeoIP.load()),
loadLazyModule(() => import('@app/features/input/state/InputKeybind')),
loadLazyModule(() => import('@app/features/auth/state/NewDeviceMonitoring')),
loadLazyModule(() => import('@app/features/ui/state/Notification')),
+1 -5
View File
@@ -2,10 +2,7 @@
import MediaEngineFacade from '@app/features/voice/engine/MediaEngineFacade';
import type {ElectronAPI} from '@app/features/platform/types/Electron';
import type {
GeolocationResponse,
InstanceDiscoveryResponse,
} from '@fluxer/instance_bootstrap/src/Types';
import type {InstanceDiscoveryResponse} from '@fluxer/instance_bootstrap/src/Types';
import {Buffer} from 'buffer';
type MediaEngineInstance = typeof MediaEngineFacade;
@@ -31,7 +28,6 @@ interface FluxerBootstrapGlobal {
bootstrapApiPublicEndpoint?: string;
};
instance: InstanceDiscoveryResponse;
geoip: GeolocationResponse;
}
declare global {
+72 -15
View File
@@ -1,38 +1,95 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
import type {GeoEntry, GeolocationResponse} from '@fluxer/instance_bootstrap/src/Types';
import {Logger} from '@app/features/platform/utils/AppLogger';
import ageGeos from '@fluxer/constants/src/AgeGeos.json';
import type {GeoEntry} from '@fluxer/instance_bootstrap/src/Types';
import {GeolocationResponse} from '@fluxer/schema/src/domains/geolocation/GeolocationSchemas';
import {makeAutoObservable, runInAction} from 'mobx';
const GEOIP_PATH = '/_geoip';
const GEOIP_ATTEMPTS = 3;
const GEOIP_ATTEMPT_TIMEOUT_MS = 2000;
const GEOIP_RETRY_DELAY_MS = 200;
const logger = new Logger('GeoIP');
interface ConnectionGeoCoordinates {
latitude: string | null;
longitude: string | null;
}
function getInlinedGeoip(): GeolocationResponse {
const bootstrap = typeof window !== 'undefined' ? window.__FLUXER_BOOTSTRAP__ : undefined;
if (!bootstrap) {
throw new Error('window.__FLUXER_BOOTSTRAP__ is missing — app must be served by fluxer_app_proxy');
}
return bootstrap.geoip;
const UNRESOLVED_GEOIP: GeolocationResponse = {
countryCode: null,
regionCode: null,
latitude: null,
longitude: null,
ageRestrictedGeos: ageGeos.ageRestrictedGeos,
ageBlockedGeos: ageGeos.ageBlockedGeos,
};
function wait(ms: number): Promise<void> {
return new Promise((resolve) => setTimeout(resolve, ms));
}
async function fetchGeoipOnce(): Promise<GeolocationResponse> {
const controller = new AbortController();
const timer = setTimeout(() => controller.abort(), GEOIP_ATTEMPT_TIMEOUT_MS);
try {
const response = await fetch(GEOIP_PATH, {
cache: 'no-store',
credentials: 'omit',
headers: {Accept: 'application/json'},
signal: controller.signal,
});
if (!response.ok) {
throw new Error(`GeoIP lookup failed with status ${response.status}`);
}
return GeolocationResponse.parse(await response.json());
} finally {
clearTimeout(timer);
}
}
async function fetchGeoip(): Promise<GeolocationResponse> {
for (let attempt = 1; ; attempt++) {
try {
return await fetchGeoipOnce();
} catch (error) {
if (attempt >= GEOIP_ATTEMPTS) {
logger.warn('GeoIP lookup failed, continuing without a location:', error);
return UNRESOLVED_GEOIP;
}
await wait(GEOIP_RETRY_DELAY_MS * attempt);
}
}
}
let loading: Promise<void> | null = null;
class GeoIP {
countryCode: string | null;
regionCode: string | null;
latitude: string | null;
longitude: string | null;
ageRestrictedGeos: ReadonlyArray<GeoEntry>;
ageBlockedGeos: ReadonlyArray<GeoEntry>;
countryCode: string | null = UNRESOLVED_GEOIP.countryCode;
regionCode: string | null = UNRESOLVED_GEOIP.regionCode;
latitude: string | null = UNRESOLVED_GEOIP.latitude;
longitude: string | null = UNRESOLVED_GEOIP.longitude;
ageRestrictedGeos: ReadonlyArray<GeoEntry> = UNRESOLVED_GEOIP.ageRestrictedGeos;
ageBlockedGeos: ReadonlyArray<GeoEntry> = UNRESOLVED_GEOIP.ageBlockedGeos;
constructor() {
const data = getInlinedGeoip();
makeAutoObservable(this, {}, {autoBind: true});
}
load(): Promise<void> {
loading ??= fetchGeoip().then((data) => {
runInAction(() => {
this.countryCode = data.countryCode;
this.regionCode = data.regionCode;
this.latitude = data.latitude;
this.longitude = data.longitude;
this.ageRestrictedGeos = data.ageRestrictedGeos;
this.ageBlockedGeos = data.ageBlockedGeos;
makeAutoObservable(this, {}, {autoBind: true});
});
});
return loading;
}
applyConnectionFallbackCoordinates(data: ConnectionGeoCoordinates): void {
@@ -19,14 +19,14 @@ const UNRENDERED_INDEX_TEMPLATE = [
'<!doctype html><html lang="en"><head>',
'<link rel="preconnect" href="{{STATIC_CDN_ENDPOINT}}">',
'<link rel="apple-touch-icon" href="{{STATIC_CDN_ENDPOINT}}/web/apple-touch-icon.png">',
'<script nonce="{{CSP_NONCE_PLACEHOLDER}}"></script>',
'<script></script>',
'</head><body><div id="root"></div></body></html>',
].join('');
const RENDERED_INDEX_DOCUMENT = [
'<!doctype html><html lang="en"><head>',
'<link rel="preconnect" href="https://cdn.fluxer.test">',
'<script nonce="abc123">window.__FLUXER_BOOTSTRAP__={"instance":{}};</script>',
'<script>window.__FLUXER_BOOTSTRAP__={"instance":{}};</script>',
'</head><body><div id="root"></div></body></html>',
].join('');
@@ -344,14 +344,6 @@ const BOOTSTRAP_ENDPOINT = 'https://primary.test/api';
registration: {collect_date_of_birth: true},
},
},
geoip: {
countryCode: null,
regionCode: null,
latitude: null,
longitude: null,
ageRestrictedGeos: [],
ageBlockedGeos: [],
},
};
const {VoiceEngineV2AppScreenShareExecutionAdapter, shouldRestoreScreenShareAfterReconnect} = await import(
+1
View File
@@ -16,6 +16,7 @@ rand = "0.10"
reqwest = { version = "0.13.5", default-features = false, features = ["json", "rustls", "stream", "gzip", "brotli", "deflate"] }
serde = { version = "1.0.229", features = ["derive"] }
serde_json = "1.0.151"
sha2 = "0.11.0"
tokio = { version = "1.53.1", features = ["macros", "net", "rt-multi-thread", "signal", "time", "fs"] }
tokio-util = { version = "0.7.19", features = ["io"] }
tower = { version = "0.5.3", features = ["util"] }
+39 -54
View File
@@ -9,7 +9,6 @@ use serde::Serialize;
pub struct BootstrapPayload<'a> {
pub config: BootstrapConfig<'a>,
pub instance: &'a serde_json::Value,
pub geoip: &'a serde_json::Value,
}
#[derive(Serialize)]
@@ -38,12 +37,7 @@ struct LegacyConfig<'a> {
bootstrap_api_public_endpoint: Option<&'a str>,
}
pub fn build_bootstrap_script(
config: &AppProxyConfig,
discovery: &DiscoveryResponse,
geoip: &serde_json::Value,
nonce: &str,
) -> String {
pub fn build_bootstrap_script(config: &AppProxyConfig, discovery: &DiscoveryResponse) -> String {
let api_public_endpoint =
api_public_endpoint(config.bootstrap_api_public_endpoint.as_deref(), discovery);
@@ -54,7 +48,6 @@ pub fn build_bootstrap_script(
bootstrap_api_public_endpoint: api_public_endpoint,
},
instance: &discovery.data,
geoip,
};
let legacy = LegacyConfig {
@@ -67,7 +60,7 @@ pub fn build_bootstrap_script(
let legacy_json = escape_json_for_script(&serde_json::to_string(&legacy).unwrap());
format!(
r#"<script nonce="{nonce}">window.__FLUXER_BOOTSTRAP__={bootstrap_json};window.__FLUXER_CONFIG__={legacy_json};</script>"#
r#"<script>window.__FLUXER_BOOTSTRAP__={bootstrap_json};window.__FLUXER_CONFIG__={legacy_json};</script>"#
)
}
@@ -144,7 +137,6 @@ const STATIC_PRECONNECT_TAGS: [&str; 2] = [
pub fn inject_bootstrap(
html: &str,
nonce: &str,
script_tag: &str,
static_cdn_endpoint: &str,
media_endpoint: &str,
@@ -152,35 +144,34 @@ pub fn inject_bootstrap(
let static_cdn = static_cdn_endpoint.trim_end_matches('/');
let media = media_endpoint.trim_end_matches('/');
let nonced = html.replace("{{CSP_NONCE_PLACEHOLDER}}", nonce);
let nonced = apply_static_preconnect(nonced, static_cdn);
let nonced = nonced.replace("{{STATIC_CDN_ENDPOINT}}", static_cdn);
let nonced = apply_media_preconnect(&nonced, media, static_cdn);
let html = apply_static_preconnect(html.to_owned(), static_cdn);
let html = html.replace("{{STATIC_CDN_ENDPOINT}}", static_cdn);
let html = apply_media_preconnect(&html, media, static_cdn);
if nonced.contains("<!--{{FLUXER_BOOTSTRAP}}-->") {
return nonced.replace("<!--{{FLUXER_BOOTSTRAP}}-->", script_tag);
if html.contains("<!--{{FLUXER_BOOTSTRAP}}-->") {
return html.replace("<!--{{FLUXER_BOOTSTRAP}}-->", script_tag);
}
if nonced.contains("{{FLUXER_BOOTSTRAP}}") {
return nonced.replace("{{FLUXER_BOOTSTRAP}}", script_tag);
if html.contains("{{FLUXER_BOOTSTRAP}}") {
return html.replace("{{FLUXER_BOOTSTRAP}}", script_tag);
}
let insert_at = nonced
let insert_at = html
.find("<head>")
.map(|pos| pos + "<head>".len())
.or_else(|| {
let pos = nonced.find("<head ")?;
nonced[pos..].find('>').map(|close| pos + close + 1)
let pos = html.find("<head ")?;
html[pos..].find('>').map(|close| pos + close + 1)
});
if let Some(insert_at) = insert_at {
let mut result = String::with_capacity(nonced.len() + script_tag.len() + 3);
result.push_str(&nonced[..insert_at]);
let mut result = String::with_capacity(html.len() + script_tag.len() + 3);
result.push_str(&html[..insert_at]);
result.push_str("\n\t\t");
result.push_str(script_tag);
result.push_str(&nonced[insert_at..]);
result.push_str(&html[insert_at..]);
return result;
}
nonced
html
}
fn apply_static_preconnect(mut html: String, static_cdn: &str) -> String {
@@ -219,7 +210,6 @@ mod tests {
fn inject_into_shipped_shell() -> String {
inject_bootstrap(
SHIPPED_APP_SHELL,
"shellnonce",
"<script>boot</script>",
"https://cdn.example.test/",
"https://media.example.test/",
@@ -256,16 +246,20 @@ mod tests {
let result = inject_into_shipped_shell();
assert!(!result.contains("{{STATIC_CDN_ENDPOINT}}"));
assert!(!result.contains("{{MEDIA_ENDPOINT}}"));
assert!(!result.contains("{{CSP_NONCE_PLACEHOLDER}}"));
assert!(!result.contains("{{FLUXER_BOOTSTRAP}}"));
assert!(result.contains("<script>boot</script>"));
assert!(result.contains(r#"nonce="shellnonce""#));
}
#[test]
fn shipped_shell_carries_no_nonce_attribute_or_placeholder() {
assert!(!SHIPPED_APP_SHELL.contains("nonce"));
assert!(!SHIPPED_APP_SHELL.contains("{{CSP_NONCE_PLACEHOLDER}}"));
}
#[test]
fn inject_bootstrap_before_head_close() {
let html = "<html><head><title>App</title></head><body></body></html>";
let result = inject_bootstrap(html, "abc123", "<script>boot</script>", "", "");
let result = inject_bootstrap(html, "<script>boot</script>", "", "");
assert!(result.contains("<script>boot</script>"));
assert!(result.contains("<head>"));
}
@@ -273,7 +267,7 @@ mod tests {
#[test]
fn inject_bootstrap_fluxer_placeholder() {
let html = "<html><head>{{FLUXER_BOOTSTRAP}}</head></html>";
let result = inject_bootstrap(html, "n1", "<script>x</script>", "", "");
let result = inject_bootstrap(html, "<script>x</script>", "", "");
assert!(result.contains("<script>x</script>"));
assert!(!result.contains("{{FLUXER_BOOTSTRAP}}"));
}
@@ -281,25 +275,16 @@ mod tests {
#[test]
fn inject_bootstrap_comment_placeholder() {
let html = "<html><head><!--{{FLUXER_BOOTSTRAP}}--></head></html>";
let result = inject_bootstrap(html, "n2", "<script>y</script>", "", "");
let result = inject_bootstrap(html, "<script>y</script>", "", "");
assert!(result.contains("<script>y</script>"));
assert!(!result.contains("<!--{{FLUXER_BOOTSTRAP}}-->"));
}
#[test]
fn inject_bootstrap_replaces_csp_nonce_placeholder() {
let html = r#"<html><head><script nonce="{{CSP_NONCE_PLACEHOLDER}}"></script>{{FLUXER_BOOTSTRAP}}</head></html>"#;
let result = inject_bootstrap(html, "mynonce", "<script>z</script>", "", "");
assert!(result.contains(r#"nonce="mynonce""#));
assert!(!result.contains("{{CSP_NONCE_PLACEHOLDER}}"));
}
#[test]
fn inject_bootstrap_replaces_static_cdn_endpoint_placeholder() {
let html = r#"<html><head><link href="{{STATIC_CDN_ENDPOINT}}/web/favicon-32x32.png">{{FLUXER_BOOTSTRAP}}</head></html>"#;
let result = inject_bootstrap(
html,
"nonce",
"<script>boot</script>",
"https://cdn.example.test/",
"",
@@ -315,7 +300,6 @@ mod tests {
{{FLUXER_BOOTSTRAP}}</head></html>"#;
let result = inject_bootstrap(
html,
"nonce",
"<script>boot</script>",
"https://cdn.example.test/",
"https://media.example.test/",
@@ -332,7 +316,6 @@ mod tests {
{{FLUXER_BOOTSTRAP}}</head></html>"#;
let result = inject_bootstrap(
html,
"nonce",
"<script>boot</script>",
"https://cdn.example.test",
"",
@@ -349,7 +332,6 @@ mod tests {
{{FLUXER_BOOTSTRAP}}</head></html>"#;
let result = inject_bootstrap(
html,
"nonce",
"<script>boot</script>",
"https://cdn.example.test",
"https://cdn.example.test/",
@@ -367,7 +349,6 @@ mod tests {
fn static_cdn_keeps_a_credentialed_and_an_anonymous_preconnect() {
let result = inject_bootstrap(
SHELL_PRECONNECT_HEAD,
"nonce",
"<script>boot</script>",
"https://cdn.example.test/",
"https://media.example.test",
@@ -384,7 +365,6 @@ mod tests {
fn both_static_preconnects_are_dropped_when_the_endpoint_is_empty() {
let result = inject_bootstrap(
SHELL_PRECONNECT_HEAD,
"nonce",
"<script>boot</script>",
"",
"https://media.example.test",
@@ -422,7 +402,6 @@ mod tests {
#[test]
fn bootstrap_payload_serialization_field_names() {
let instance = serde_json::json!({"name": "test"});
let geoip = serde_json::json!({"country": "SE"});
let payload = BootstrapPayload {
config: BootstrapConfig {
release_channel: "stable",
@@ -430,20 +409,18 @@ mod tests {
bootstrap_api_public_endpoint: None,
},
instance: &instance,
geoip: &geoip,
};
let json = serde_json::to_string(&payload).unwrap();
assert!(json.contains(r#""releaseChannel""#));
assert!(json.contains(r#""bootstrapApiEndpoint""#));
assert!(json.contains(r#""config""#));
assert!(json.contains(r#""instance""#));
assert!(json.contains(r#""geoip""#));
assert!(!json.contains("geoip"));
}
#[test]
fn bootstrap_config_serializes_public_endpoint_when_present() {
let instance = serde_json::json!({});
let geoip = serde_json::json!({});
let payload = BootstrapPayload {
config: BootstrapConfig {
release_channel: "canary",
@@ -451,7 +428,6 @@ mod tests {
bootstrap_api_public_endpoint: Some("https://pub.example.com/api"),
},
instance: &instance,
geoip: &geoip,
};
let json = serde_json::to_string(&payload).unwrap();
assert!(json.contains(r#""bootstrapApiPublicEndpoint""#));
@@ -460,7 +436,6 @@ mod tests {
#[test]
fn bootstrap_config_omits_public_endpoint_when_none() {
let instance = serde_json::json!({});
let geoip = serde_json::json!({});
let payload = BootstrapPayload {
config: BootstrapConfig {
release_channel: "stable",
@@ -468,7 +443,6 @@ mod tests {
bootstrap_api_public_endpoint: None,
},
instance: &instance,
geoip: &geoip,
};
let json = serde_json::to_string(&payload).unwrap();
assert!(!json.contains("bootstrapApiPublicEndpoint"));
@@ -611,8 +585,7 @@ mod tests {
let discovery = discovery_offering("https://chat.example.test:8443/api");
let mut config = AppProxyConfig::from_env();
config.bootstrap_api_public_endpoint = Some("https://chat.example.test/api".to_owned());
let script =
build_bootstrap_script(&config, &discovery, &serde_json::json!({}), "scriptnonce");
let script = build_bootstrap_script(&config, &discovery);
assert!(
script.contains(r#""bootstrapApiPublicEndpoint":"https://chat.example.test:8443/api""#)
);
@@ -621,4 +594,16 @@ mod tests {
));
assert!(!script.contains(r#""https://chat.example.test/api""#));
}
#[test]
fn the_boot_script_is_a_bare_inline_script_with_nothing_per_visitor() {
let discovery = discovery_offering("https://chat.example.test/api");
let config = AppProxyConfig::from_env();
let script = build_bootstrap_script(&config, &discovery);
assert!(script.starts_with("<script>window.__FLUXER_BOOTSTRAP__="));
assert!(script.ends_with("</script>"));
assert!(!script.contains("nonce"));
assert!(!script.contains("geoip"));
assert!(!script.contains("countryCode"));
}
}
+177 -71
View File
@@ -3,15 +3,82 @@
use crate::config::{AppProxyConfig, CspConfig, CspSource, HttpEndpoint};
use axum::http::HeaderValue;
use axum::http::header::InvalidHeaderValue;
use rand::RngExt;
use base64::{Engine as _, engine::general_purpose::STANDARD};
use sha2::{Digest, Sha256};
const CSP_NONCE_HEX_DIGITS: usize = 32;
const CSP_VALIDATION_NONCE: &str = "00000000000000000000000000000000";
#[derive(Clone, Debug, PartialEq, Eq)]
pub struct InlineScriptHash(String);
const _: () = assert!(
CSP_VALIDATION_NONCE.len() == CSP_NONCE_HEX_DIGITS,
"the nonce a policy is validated with must be shaped like the nonce a request carries"
);
impl InlineScriptHash {
pub fn of(script_text: &str) -> Self {
Self(format!(
"'sha256-{}'",
STANDARD.encode(Sha256::digest(script_text.as_bytes()))
))
}
pub fn as_source(&self) -> &str {
&self.0
}
}
pub fn inline_script_hashes(document: &str) -> Vec<InlineScriptHash> {
let mut hashes: Vec<InlineScriptHash> = Vec::new();
let mut rest = document;
while let Some((attributes, text, after)) = next_script_element(rest) {
rest = after;
if has_src_attribute(attributes) {
continue;
}
let hash = InlineScriptHash::of(text);
if !hashes.contains(&hash) {
hashes.push(hash);
}
}
hashes
}
fn next_script_element(html: &str) -> Option<(&str, &str, &str)> {
let mut offset = 0;
loop {
let start = offset + find_ignoring_ascii_case(&html[offset..], "<script")?;
let name_end = start + "<script".len();
let boundary = *html.as_bytes().get(name_end)?;
if boundary != b'>' && boundary != b'/' && !boundary.is_ascii_whitespace() {
offset = name_end;
continue;
}
let tag_end = name_end + html[name_end..].find('>')?;
let text_start = tag_end + 1;
let text_end = text_start + find_ignoring_ascii_case(&html[text_start..], "</script")?;
let close_end = html[text_end..]
.find('>')
.map_or(html.len(), |index| text_end + index + 1);
return Some((
&html[name_end..tag_end],
&html[text_start..text_end],
&html[close_end..],
));
}
}
fn find_ignoring_ascii_case(haystack: &str, needle: &str) -> Option<usize> {
haystack
.as_bytes()
.windows(needle.len())
.position(|window| window.eq_ignore_ascii_case(needle.as_bytes()))
}
fn has_src_attribute(attributes: &str) -> bool {
attributes
.split(|c: char| c.is_ascii_whitespace() || c == '/')
.any(|token| {
token
.split('=')
.next()
.is_some_and(|name| name.eq_ignore_ascii_case("src"))
})
}
#[derive(Clone, Debug, Default)]
pub struct RuntimeCspSources {
@@ -129,7 +196,7 @@ impl CompiledCspPolicy {
.map_err(CspCompileError::InvalidAssetPolicy)?;
HeaderValue::from_str(&build_csp(
&config,
CSP_VALIDATION_NONCE,
&[InlineScriptHash::of("")],
configured_sources,
))
.map_err(CspCompileError::InvalidSpaPolicy)?;
@@ -140,26 +207,24 @@ impl CompiledCspPolicy {
self.asset.clone()
}
pub fn spa_header(&self, nonce: &str, runtime_sources: &RuntimeCspSources) -> HeaderValue {
assert!(
nonce.len() == CSP_NONCE_HEX_DIGITS
&& nonce.bytes().all(|byte| byte.is_ascii_hexdigit()),
"a CSP nonce must be a 128-bit hexadecimal value"
);
HeaderValue::from_str(&build_csp(&self.config, nonce, runtime_sources)).expect(
"every CSP source is a validated keyword, scheme, or ASCII origin, so a policy built \
from them is always a valid header value",
pub fn spa_header(
&self,
script_hashes: &[InlineScriptHash],
runtime_sources: &RuntimeCspSources,
) -> HeaderValue {
HeaderValue::from_str(&build_csp(&self.config, script_hashes, runtime_sources)).expect(
"every CSP source is a validated keyword, scheme, ASCII origin, or base64 hash, so a \
policy built from them is always a valid header value",
)
}
}
pub fn generate_nonce() -> String {
let bytes: [u8; 16] = rand::rng().random();
hex::encode(bytes)
}
fn build_csp(config: &CspConfig, nonce: &str, runtime_sources: &RuntimeCspSources) -> String {
build_csp_directives(config, Some(nonce), runtime_sources).join("; ")
fn build_csp(
config: &CspConfig,
script_hashes: &[InlineScriptHash],
runtime_sources: &RuntimeCspSources,
) -> String {
build_csp_directives(config, Some(script_hashes), runtime_sources).join("; ")
}
fn build_asset_csp(config: &CspConfig, runtime_sources: &RuntimeCspSources) -> String {
@@ -168,7 +233,7 @@ fn build_asset_csp(config: &CspConfig, runtime_sources: &RuntimeCspSources) -> S
fn build_csp_directives(
config: &CspConfig,
nonce: Option<&str>,
script_hashes: Option<&[InlineScriptHash]>,
runtime_sources: &RuntimeCspSources,
) -> Vec<String> {
let mut directives = Vec::with_capacity(14);
@@ -182,8 +247,8 @@ fn build_csp_directives(
"'wasm-unsafe-eval'".to_owned(),
"blob:".to_owned(),
];
if let Some(n) = nonce {
script.insert(1, format!("'nonce-{n}'"));
if let Some(hashes) = script_hashes {
script.splice(1..1, hashes.iter().map(|hash| hash.as_source().to_owned()));
}
extend_from(&mut script, &config.extra_script_src, SCRIPT_SOURCES);
extend_runtime_sources(&mut script, runtime_sources, true, false);
@@ -290,21 +355,52 @@ fn extend_from(target: &mut Vec<String>, extra: &[CspSource], defaults: &[&str])
mod tests {
use super::*;
#[test]
fn generate_nonce_produces_32_char_hex() {
let nonce = generate_nonce();
assert_eq!(nonce.len(), CSP_NONCE_HEX_DIGITS);
assert!(nonce.chars().all(|c| c.is_ascii_hexdigit()));
CompiledCspPolicy::compile(default_csp_config(), &runtime_sources())
.unwrap()
.spa_header(&nonce, &runtime_sources());
fn hash_of(text: &str) -> InlineScriptHash {
InlineScriptHash::of(text)
}
#[test]
fn generate_nonce_is_random() {
let a = generate_nonce();
let b = generate_nonce();
assert_ne!(a, b);
fn an_inline_script_hash_is_the_base64_sha256_of_the_exact_script_text() {
assert_eq!(
hash_of("alert('Hello, world.');").as_source(),
"'sha256-qznLcsROx4GACP2dm0UCKCzCG+HiZ1guq6ZZDob/Tng='"
);
assert_eq!(
hash_of("").as_source(),
"'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU='"
);
}
#[test]
fn every_inline_script_is_hashed_and_external_scripts_are_not() {
let document = concat!(
"<head><script>first()</script>",
"<SCRIPT type=\"text/javascript\">second()</SCRIPT >",
"<script type=\"module\" src=\"/assets/app.js\"></script>",
"<script defer src='/assets/vendor.js'></script>",
"<scripts>not a script</scripts>",
"<script data-src=\"x\">\nthird()\n</script></head>",
);
assert_eq!(
inline_script_hashes(document),
vec![
hash_of("first()"),
hash_of("second()"),
hash_of("\nthird()\n")
]
);
}
#[test]
fn an_inline_script_repeated_verbatim_is_granted_once() {
let document = "<script>same()</script><script>same()</script>";
assert_eq!(inline_script_hashes(document), vec![hash_of("same()")]);
}
#[test]
fn an_unterminated_script_is_never_granted() {
assert!(inline_script_hashes("<script>never_closed()").is_empty());
}
fn default_csp_config() -> CspConfig {
@@ -322,7 +418,7 @@ mod tests {
#[test]
fn build_csp_includes_required_directives() {
let config = default_csp_config();
let csp = build_csp(&config, "testnonce", &runtime_sources());
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
assert!(csp.contains("default-src"));
assert!(csp.contains("script-src"));
assert!(csp.contains("style-src"));
@@ -341,7 +437,7 @@ mod tests {
#[test]
fn build_csp_allows_blob_connections_for_camera_background_media() {
let config = default_csp_config();
let csp = build_csp(&config, "testnonce", &runtime_sources());
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
let connect = csp
.split("; ")
.find(|directive| directive.starts_with("connect-src "))
@@ -369,22 +465,40 @@ mod tests {
}
#[test]
fn build_csp_includes_nonce_in_script_src() {
fn build_csp_grants_each_script_hash_in_script_src_and_no_nonce() {
let config = default_csp_config();
let csp = build_csp(&config, "abc123def456", &runtime_sources());
assert!(csp.contains("'nonce-abc123def456'"));
}
#[test]
fn build_asset_csp_excludes_nonce() {
let config = default_csp_config();
let csp = build_asset_csp(&config, &runtime_sources());
let csp = build_csp(
&config,
&[hash_of("first()"), hash_of("second()")],
&runtime_sources(),
);
let script = csp
.split("; ")
.find(|directive| directive.starts_with("script-src "))
.expect("script-src directive");
assert!(script.starts_with(&format!(
"script-src 'self' {} {} 'wasm-unsafe-eval' blob:",
hash_of("first()").as_source(),
hash_of("second()").as_source()
)));
assert!(!csp.contains("nonce-"));
}
#[test]
fn build_asset_csp_grants_no_inline_script() {
let config = default_csp_config();
let csp = build_asset_csp(&config, &runtime_sources());
assert!(!csp.contains("nonce-"));
assert!(!csp.contains("sha256-"));
}
#[test]
fn build_csp_allows_no_third_party_captcha_hosts() {
let csp = build_csp(&default_csp_config(), "test-nonce", &runtime_sources());
let csp = build_csp(
&default_csp_config(),
&[hash_of("boot()")],
&runtime_sources(),
);
assert!(!csp.contains("hcaptcha"));
assert!(!csp.contains("challenges.cloudflare.com"));
}
@@ -392,7 +506,7 @@ mod tests {
#[test]
fn csp_no_double_spaces_or_trailing_semicolons() {
let config = default_csp_config();
let csp = build_csp(&config, "nonce1", &runtime_sources());
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
assert!(!csp.contains(" "), "CSP contains double spaces");
assert!(!csp.ends_with(';'), "CSP ends with semicolon");
assert!(!csp.ends_with("; "), "CSP ends with semicolon+space");
@@ -410,14 +524,14 @@ mod tests {
),
..Default::default()
};
let csp = build_csp(&config, "nonce1", &runtime_sources());
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
assert!(csp.contains("report-uri https://example.com/csp-report"));
}
#[test]
fn build_csp_excludes_report_uri_when_none() {
let config = default_csp_config();
let csp = build_csp(&config, "nonce1", &runtime_sources());
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
assert!(!csp.contains("report-uri"));
}
@@ -429,7 +543,7 @@ mod tests {
media_endpoint: Some(endpoint("https://media.example.test")),
..Default::default()
};
let csp = build_csp(&config, "nonce1", &runtime_sources);
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources);
assert!(csp.contains("style-src 'self' 'unsafe-inline'"));
assert!(csp.contains("https://static.example.test"));
assert!(csp.contains("https://media.example.test"));
@@ -471,7 +585,7 @@ mod tests {
..Default::default()
};
let csp = build_csp(&config, "nonce1", &runtime_sources);
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources);
assert!(csp.contains("http://localhost:3900"));
assert!(csp.contains("http://fluxer-uploads.localhost:3900"));
@@ -492,6 +606,7 @@ mod tests {
let asset = policy.asset_header();
let asset = asset.to_str().unwrap();
assert!(!asset.contains("nonce-"));
assert!(!asset.contains("sha256-"));
assert!(asset.contains("https://static.example.test"));
assert!(
!asset.contains("https://media.example.test"),
@@ -501,7 +616,7 @@ mod tests {
}
#[test]
fn a_compiled_policy_stamps_the_requests_own_nonce_and_discovery_endpoints() {
fn a_compiled_policy_stamps_the_documents_script_hashes_and_discovery_endpoints() {
let policy = CompiledCspPolicy::compile(default_csp_config(), &runtime_sources()).unwrap();
let discovered = RuntimeCspSources {
static_cdn_endpoint: Some(endpoint("https://cdn.discovered.test")),
@@ -509,10 +624,10 @@ mod tests {
..Default::default()
};
let header = policy.spa_header("0123456789abcdef0123456789abcdef", &discovered);
let header = policy.spa_header(&[hash_of("boot()")], &discovered);
let header = header.to_str().unwrap();
assert!(header.contains("'nonce-0123456789abcdef0123456789abcdef'"));
assert!(header.contains(hash_of("boot()").as_source()));
assert!(header.contains("https://cdn.discovered.test"));
assert!(header.contains("https://branding.discovered.test"));
}
@@ -530,19 +645,10 @@ mod tests {
policy.asset_header().to_str().unwrap(),
build_asset_csp(&config, &sources)
);
let hashes = [hash_of("boot()")];
assert_eq!(
policy
.spa_header(CSP_VALIDATION_NONCE, &sources)
.to_str()
.unwrap(),
build_csp(&config, CSP_VALIDATION_NONCE, &sources)
policy.spa_header(&hashes, &sources).to_str().unwrap(),
build_csp(&config, &hashes, &sources)
);
}
#[test]
#[should_panic(expected = "a CSP nonce must be a 128-bit hexadecimal value")]
fn a_compiled_policy_refuses_a_nonce_it_did_not_generate() {
let policy = CompiledCspPolicy::compile(default_csp_config(), &runtime_sources()).unwrap();
policy.spa_header("not-a-nonce", &runtime_sources());
}
}
@@ -0,0 +1,97 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
use crate::geoip::build_geoip_response;
use crate::state::AppState;
use axum::{
Json,
extract::State,
http::{HeaderMap, HeaderValue, header},
response::{IntoResponse, Response},
};
pub const CLIENT_GEOIP_PATH: &str = "/_geoip";
const CLIENT_GEOIP_CACHE_CONTROL: &str = "no-store, private";
pub async fn client_geoip(State(state): State<AppState>, headers: HeaderMap) -> Response {
let mut response = Json(build_geoip_response(state.geoip.lookup(&headers))).into_response();
response.headers_mut().insert(
header::CACHE_CONTROL,
HeaderValue::from_static(CLIENT_GEOIP_CACHE_CONTROL),
);
response
}
#[cfg(test)]
mod tests {
use super::*;
use crate::config::AppProxyConfig;
use crate::discovery_cache::DiscoveryCache;
use crate::routes::build_router;
use axum::body::Body;
use axum::http::{Request, StatusCode};
use fluxer_common::config::GeoipSourceConfig;
use fluxer_common::geoip::{GeoipConfig, GeoipLookup, GeoipResolver};
use std::sync::Arc;
use tower::ServiceExt;
fn geoip_state() -> AppState {
let config = AppProxyConfig::from_env();
let csp = Arc::new(
crate::csp::CompiledCspPolicy::from_config(&config)
.expect("the test configuration must compile to a valid CSP"),
);
AppState {
config: Arc::new(config),
csp,
http_client: reqwest::Client::new(),
discovery_cache: Arc::new(DiscoveryCache::new()),
geoip: Arc::new(GeoipResolver::from_config(&GeoipConfig {
geoip_source: GeoipSourceConfig::Filesystem {
maxmind_db_path: None,
},
geoip_s3_config: None,
trust_client_ip_header: true,
client_ip_header_name: "x-forwarded-for".to_owned(),
})),
index_html: Some(Arc::from("<html><head></head><body></body></html>")),
budgets: crate::state::AppProxyBudgets::default(),
}
}
#[tokio::test]
async fn the_geoip_endpoint_answers_for_the_requesting_client_and_is_never_stored() {
let response = build_router(geoip_state())
.oneshot(
Request::get(CLIENT_GEOIP_PATH)
.header("x-forwarded-for", "203.0.113.10")
.body(Body::empty())
.unwrap(),
)
.await
.unwrap();
assert_eq!(response.status(), StatusCode::OK);
let headers = response.headers();
assert_eq!(
headers.get(header::CACHE_CONTROL).unwrap(),
CLIENT_GEOIP_CACHE_CONTROL
);
assert!(
headers
.get(header::CONTENT_TYPE)
.unwrap()
.to_str()
.unwrap()
.starts_with("application/json"),
"the SPA fallback answered the geoip endpoint with the app shell"
);
assert!(headers.get("x-fluxer-app-shell").is_none());
let body = axum::body::to_bytes(response.into_body(), usize::MAX)
.await
.unwrap();
let body: serde_json::Value = serde_json::from_slice(&body).unwrap();
assert_eq!(body, build_geoip_response(GeoipLookup::default()));
assert_eq!(body["countryCode"], serde_json::Value::Null);
}
}
+5
View File
@@ -3,6 +3,7 @@
mod android_association;
mod apple_association;
mod assets_proxy;
mod client_geoip;
mod file_stream;
mod health;
mod spa_index;
@@ -35,6 +36,10 @@ pub fn build_router(state: AppState) -> Router {
Router::new()
.route("/_health", get(health::health))
.route("/_ready", get(health::ready))
.route(
client_geoip::CLIENT_GEOIP_PATH,
get(client_geoip::client_geoip),
)
.route(
"/.well-known/apple-app-site-association",
get(apple_association::apple_app_site_association),
+172 -55
View File
@@ -4,9 +4,8 @@ use crate::bootstrap::{
build_bootstrap_script, inject_bootstrap, rewrite_endpoints_for_same_origin_host,
};
use crate::config::{AppProxyConfig, HttpEndpoint};
use crate::csp::{RuntimeCspSources, generate_nonce};
use crate::csp::{RuntimeCspSources, inline_script_hashes};
use crate::discovery_cache::{DiscoveryResponse, discovery_endpoint};
use crate::geoip::build_geoip_response;
use crate::state::{
AppProxyBudgets, AppState, MAX_RENDERED_SPA_INDEX_BYTES, MAX_SPA_INDEX_BYTES,
read_bounded_text_file,
@@ -27,6 +26,7 @@ use super::spa_static::{CORS_ALLOW_ANY_VALUE, guess_mime, is_font_mime};
const ACCEPT_CH_VALUE: &str = "DPR, Sec-CH-DPR, Sec-CH-Width, Save-Data, ECT, Downlink";
const CRITICAL_CH_VALUE: &str = "Sec-CH-DPR, Sec-CH-Width, Save-Data";
const DEV_NO_STORE_CACHE_CONTROL: &str = "no-store, no-cache, must-revalidate, max-age=0";
const SHARED_SHELL_CACHE_CONTROL: &str = "public, max-age=0, s-maxage=1";
pub async fn spa_catch_all(
State(state): State<AppState>,
@@ -154,7 +154,6 @@ async fn serve_spa_index(state: &AppState, headers: &HeaderMap) -> Response {
rewrite_endpoints_for_same_origin_host(&mut discovery.data, host);
}
let nonce = generate_nonce();
let runtime_csp_sources = build_runtime_csp_sources(state, &discovery);
let static_cdn_endpoint = runtime_csp_sources
.static_cdn_endpoint
@@ -164,9 +163,7 @@ async fn serve_spa_index(state: &AppState, headers: &HeaderMap) -> Response {
.media_endpoint
.as_ref()
.map_or("", HttpEndpoint::as_str);
let csp = state.csp.spa_header(&nonce, &runtime_csp_sources);
let geoip = build_geoip_response(state.geoip.lookup(headers));
let script_tag = build_bootstrap_script(&state.config, &discovery, &geoip, &nonce);
let script_tag = build_bootstrap_script(&state.config, &discovery);
let raw_html = match load_spa_index_html(state).await {
Ok(content) => content,
@@ -181,7 +178,6 @@ async fn serve_spa_index(state: &AppState, headers: &HeaderMap) -> Response {
let dev_buster = should_bust_dev_assets.then(current_dev_asset_cache_buster);
let html = match render_spa_document(
&raw_html,
&nonce,
&script_tag,
static_cdn_endpoint,
media_endpoint,
@@ -193,8 +189,10 @@ async fn serve_spa_index(state: &AppState, headers: &HeaderMap) -> Response {
return StatusCode::INTERNAL_SERVER_ERROR.into_response();
}
};
let html = html.into_boxed_str();
build_spa_response(html, csp, should_bust_dev_assets)
let csp = state
.csp
.spa_header(&inline_script_hashes(&html), &runtime_csp_sources);
build_spa_response(html.into_boxed_str(), csp, should_bust_dev_assets)
}
fn same_origin_host<'a>(config: &'a AppProxyConfig, headers: &HeaderMap) -> Option<&'a str> {
@@ -248,7 +246,6 @@ fn bounded_document(document: String) -> Result<String, SpaDocumentSizeLimitErro
fn render_spa_document(
html: &str,
nonce: &str,
script_tag: &str,
static_cdn_endpoint: &str,
media_endpoint: &str,
@@ -256,7 +253,6 @@ fn render_spa_document(
) -> Result<String, SpaDocumentSizeLimitError> {
let mut document = bounded_document(inject_bootstrap(
html,
nonce,
script_tag,
static_cdn_endpoint,
media_endpoint,
@@ -457,7 +453,10 @@ fn build_spa_response(html: Box<str>, csp: HeaderValue, dev_no_store: bool) -> R
HeaderValue::from_static("no-store"),
);
} else {
headers.insert(header::CACHE_CONTROL, HeaderValue::from_static("no-cache"));
headers.insert(
header::CACHE_CONTROL,
HeaderValue::from_static(SHARED_SHELL_CACHE_CONTROL),
);
}
super::set_security_headers(headers);
headers.insert(
@@ -664,13 +663,12 @@ mod tests {
assert!(!is_static_root_file("/users/1.2.3"));
}
const SHELL_WITH_A_NONCE_HOLE: &str = r#"<!doctype html><html><head><title>Fluxer</title><script nonce="{{CSP_NONCE_PLACEHOLDER}}"></script><script src="/assets/app.js"></script></head><body></body></html>"#;
const SHELL_WITH_AN_INLINE_SCRIPT: &str = r#"<!doctype html><html><head><title>Fluxer</title><script>inline()</script><script src="/assets/app.js"></script></head><body></body></html>"#;
#[test]
fn the_rendered_document_always_carries_the_bootstrap_and_a_real_nonce() {
fn the_rendered_document_always_carries_the_bootstrap() {
let rendered = render_spa_document(
SHELL_WITH_A_NONCE_HOLE,
"reqnonce",
SHELL_WITH_AN_INLINE_SCRIPT,
"<script>booted</script>",
"https://static.example.test",
"",
@@ -678,16 +676,15 @@ mod tests {
)
.expect("test SPA document must render within its size limit");
assert!(!rendered.contains("{{CSP_NONCE_PLACEHOLDER}}"));
assert!(rendered.contains(r#"nonce="reqnonce""#));
assert!(rendered.contains("<script>booted</script>"));
assert!(rendered.contains("<script>inline()</script>"));
assert!(!rendered.contains("nonce"));
}
#[test]
fn the_dev_cache_buster_reaches_the_rendered_document_only_when_supplied() {
let busted = render_spa_document(
SHELL_WITH_A_NONCE_HOLE,
"reqnonce",
SHELL_WITH_AN_INLINE_SCRIPT,
"<script>booted</script>",
"",
"",
@@ -695,8 +692,7 @@ mod tests {
)
.expect("test SPA document must render within its size limit");
let untouched = render_spa_document(
SHELL_WITH_A_NONCE_HOLE,
"reqnonce",
SHELL_WITH_AN_INLINE_SCRIPT,
"<script>booted</script>",
"",
"",
@@ -712,13 +708,12 @@ mod tests {
const SHELL_WITH_ENDPOINT_HOLES: &str = r#"<!doctype html><html><head><title>Fluxer</title><link rel="preconnect" href="{{STATIC_CDN_ENDPOINT}}">
<link rel="preconnect" href="{{STATIC_CDN_ENDPOINT}}" crossorigin>
<link rel="preconnect" href="{{MEDIA_ENDPOINT}}">
<link rel="icon" type="image/png" sizes="32x32" href="{{STATIC_CDN_ENDPOINT}}/web/favicon-32x32.png"><link rel="apple-touch-icon" sizes="180x180" href="{{STATIC_CDN_ENDPOINT}}/web/apple-touch-icon.png"><script nonce="{{CSP_NONCE_PLACEHOLDER}}"></script><script src="/assets/app.js"></script></head><body></body></html>"#;
<link rel="icon" type="image/png" sizes="32x32" href="{{STATIC_CDN_ENDPOINT}}/web/favicon-32x32.png"><link rel="apple-touch-icon" sizes="180x180" href="{{STATIC_CDN_ENDPOINT}}/web/apple-touch-icon.png"><script>inline()</script><script src="/assets/app.js"></script></head><body></body></html>"#;
#[test]
fn the_static_cdn_argument_resolves_every_hole_the_shell_carries() {
let rendered = render_spa_document(
SHELL_WITH_ENDPOINT_HOLES,
"reqnonce",
"<script>booted</script>",
"https://cdn.example.test/",
"https://media.example.test",
@@ -751,7 +746,6 @@ mod tests {
fn the_media_argument_is_resolved_and_weighed_against_the_static_cdn() {
let distinct = render_spa_document(
SHELL_WITH_ENDPOINT_HOLES,
"reqnonce",
"<script>booted</script>",
"https://cdn.example.test",
"https://media.example.test/",
@@ -767,7 +761,6 @@ mod tests {
let shared = render_spa_document(
SHELL_WITH_ENDPOINT_HOLES,
"reqnonce",
"<script>booted</script>",
"https://cdn.example.test",
"https://cdn.example.test",
@@ -934,21 +927,72 @@ mod tests {
}
}
fn nonce_granted_by(response: &Response) -> String {
let policy = response
fn policy_of(response: &Response) -> String {
response
.headers()
.get(header::CONTENT_SECURITY_POLICY)
.expect("the document was served without a content security policy")
.to_str()
.unwrap();
let opening = policy
.find("'nonce-")
.expect("the content security policy granted no nonce at all");
let remainder = &policy[opening + "'nonce-".len()..];
let closing = remainder
.find('\'')
.expect("the content security policy left its nonce source unterminated");
remainder[..closing].to_owned()
.unwrap()
.to_owned()
}
fn script_hashes_granted_by(policy: &str) -> Vec<String> {
policy
.split("; ")
.find(|directive| directive.starts_with("script-src "))
.expect("the content security policy has no script-src directive")
.split(' ')
.filter(|source| source.starts_with("'sha256-"))
.map(str::to_owned)
.collect()
}
fn bare_inline_scripts_in(document: &str) -> Vec<&str> {
document
.split("<script>")
.skip(1)
.map(|rest| {
&rest[..rest
.find("</script>")
.expect("an inline script in the served document is never closed")]
})
.collect()
}
fn sha256_source(text: &str) -> String {
use base64::Engine as _;
use sha2::Digest as _;
format!(
"'sha256-{}'",
base64::engine::general_purpose::STANDARD.encode(sha2::Sha256::digest(text))
)
}
fn assert_every_inline_script_is_granted(document: &str, policy: &str) {
for tag in document.split("<script").skip(1) {
let tag = &tag[..tag.find('>').unwrap()];
assert!(
tag.is_empty() || tag.contains(" src="),
"the served document carries a script tag the test cannot classify: <script{tag}>"
);
}
let inline = bare_inline_scripts_in(document);
assert!(
!inline.is_empty(),
"the served document carries no inline script at all"
);
let mut expected: Vec<String> = inline.iter().map(|script| sha256_source(script)).collect();
expected.sort();
expected.dedup();
let mut granted = script_hashes_granted_by(policy);
granted.sort();
assert_eq!(
granted, expected,
"the policy must grant exactly the inline scripts the document carries"
);
assert!(!document.contains("nonce"));
assert!(!policy.contains("nonce"));
}
async fn read_document(response: Response) -> String {
@@ -1059,26 +1103,14 @@ mod tests {
let response = serve_spa_index(&state, &HeaderMap::new()).await;
assert_eq!(response.status(), StatusCode::OK);
let granted_nonce = nonce_granted_by(&response);
let policy = policy_of(&response);
let served = read_document(response).await;
assert!(
!served.contains("{{CSP_NONCE_PLACEHOLDER}}"),
"the live branch shipped an unfilled nonce hole"
);
assert!(
served.contains(&format!(
r#"<script nonce="{granted_nonce}">window.__FLUXER_BOOTSTRAP__"#
)),
"the live bootstrap was not granted the nonce its own policy header carries"
);
assert_eq!(
served
.matches(&format!(r#"nonce="{granted_nonce}""#))
.count(),
served.matches(r#"nonce=""#).count(),
"the live document carries a nonce its own policy header never granted"
served.contains("<script>window.__FLUXER_BOOTSTRAP__"),
"the live bootstrap is not a bare inline script"
);
assert_every_inline_script_is_granted(&served, &policy);
assert!(
!served.contains("{{STATIC_CDN_ENDPOINT}}"),
"the live branch shipped an unresolved static CDN hole"
@@ -1159,9 +1191,11 @@ mod tests {
.to_str()
.unwrap();
assert_eq!(
cache_control, "no-cache",
"the document naming the hashed bundle must be revalidated on every load"
cache_control, SHARED_SHELL_CACHE_CONTROL,
"the document naming the hashed bundle must be revalidated on every load and held \
by a shared cache for one second at most"
);
assert!(response.headers().get(header::SET_COOKIE).is_none());
assert_ne!(
cache_control, LONG_LIVED_ASSET_CACHE_CONTROL,
"a shell cached for a year pins every returning visitor to the deployed-over bundle"
@@ -1254,6 +1288,89 @@ mod tests {
);
}
fn request_from_visitor(ip: &str, country: &str, language: &str) -> HeaderMap {
let mut headers = request_from_host("web.fluxer.app");
for (name, value) in [
("x-forwarded-for", ip),
("cf-connecting-ip", ip),
("cf-ipcountry", country),
("accept-language", language),
("cookie", "session=visitor-specific"),
] {
headers.insert(
HeaderName::from_static(name),
HeaderValue::from_str(value).unwrap(),
);
}
headers
}
#[tokio::test]
async fn every_visitor_to_a_host_gets_a_byte_identical_shell_and_policy() {
let mut state = assemble_spa_state(
ReleaseChannel::Stable,
Some(SHIPPED_APP_SHELL),
DISCOVERY_BODY_WITH_WEB_APP_ENDPOINTS,
None,
None,
)
.await;
let mut config = (*state.config).clone();
config.same_origin_hosts = vec!["web.fluxer.app".to_owned()];
config.trust_client_ip_header = true;
state.config = Arc::new(config);
let stockholm =
serve_spa_index(&state, &request_from_visitor("81.234.0.1", "SE", "sv-SE")).await;
let sao_paulo =
serve_spa_index(&state, &request_from_visitor("177.0.0.1", "BR", "pt-BR")).await;
assert_eq!(stockholm.status(), StatusCode::OK);
assert_eq!(sao_paulo.status(), StatusCode::OK);
let stockholm_policy = policy_of(&stockholm);
let sao_paulo_policy = policy_of(&sao_paulo);
assert_eq!(stockholm_policy, sao_paulo_policy);
assert!(stockholm.headers().get(header::SET_COOKIE).is_none());
assert!(sao_paulo.headers().get(header::SET_COOKIE).is_none());
let stockholm_body = read_document(stockholm).await;
let sao_paulo_body = read_document(sao_paulo).await;
assert_eq!(stockholm_body, sao_paulo_body);
assert!(!stockholm_body.contains("geoip"));
assert!(!stockholm_body.contains("countryCode"));
assert_every_inline_script_is_granted(&stockholm_body, &stockholm_policy);
}
#[tokio::test]
async fn the_shipped_shell_runs_every_inline_script_it_carries_under_its_policy() {
let state = spa_state_serving(ReleaseChannel::Stable, Some(SHIPPED_APP_SHELL)).await;
let response = serve_spa_index(&state, &HeaderMap::new()).await;
assert_eq!(response.status(), StatusCode::OK);
let policy = policy_of(&response);
let served = read_document(response).await;
assert_eq!(
bare_inline_scripts_in(&served).len(),
bare_inline_scripts_in(SHIPPED_APP_SHELL).len() + 1,
"every inline script of fluxer_app/index.html plus the bootstrap must reach the document"
);
assert_every_inline_script_is_granted(&served, &policy);
}
#[tokio::test]
async fn an_index_upstream_document_is_granted_after_its_dev_cache_buster() {
let index_upstream_url = spawn_local_origin(SHIPPED_APP_SHELL, "text/html").await;
let state = spa_state_reading_its_shell_from(index_upstream_url).await;
let response = serve_spa_index(&state, &HeaderMap::new()).await;
assert_eq!(response.status(), StatusCode::OK);
let policy = policy_of(&response);
let served = read_document(response).await;
assert_every_inline_script_is_granted(&served, &policy);
}
#[test]
fn font_mime_types_are_cors_enabled() {
assert!(is_font_mime("font/woff2"));
@@ -1570,7 +1570,7 @@ Defaults to the crate version. The reported build of `admin` and `app-proxy`. `B
## Content Security Policy
`app-proxy` builds a per-request nonce-based policy for the client HTML and the assets it serves. Each variable appends sources to one directive on top of the built-in ones. All are empty by default, and Compose forwards every one.
`app-proxy` builds the policy for the client HTML and the assets it serves. The client HTML policy allows each inline script by its SHA-256 hash, so every visitor to a host gets the same document and header. Each variable appends sources to one directive on top of the built-in ones. All are empty by default, and Compose forwards every one.
Every name below goes in `.env`. `app-proxy` reads its environment at container start, so a change takes effect on `docker compose up -d app-proxy`. A `docker compose restart app-proxy` does not apply it.
@@ -395,6 +395,7 @@ Forward every path and query string unchanged. The edge handles routing:
| `/.well-known/apple-app-site-association`, `/apple-app-site-association` | Apple app association |
| `/.well-known/assetlinks.json` | Android app association |
| `/version.json` | Client version metadata |
| `/_geoip` | Client location lookup |
All other paths serve the web app. The admin path follows `FLUXER_ADMIN_BASE_PATH`, `/admin` by default.