4 ms·
This is the second post I’ve seen praising Datastar in the last 24 hours, and once again no mention of the requirement to punch a gaping hole in one’s Content-S
by j13n 1y ago
This is the second post I’ve seen praising Datastar in the last 24 hours, and once again no mention of the requirement to punch a gaping hole in one’s Content-Security-Policy.
If this is the framework of the future, cyber criminals are going to have a bright future!
- max_ 1y agoHow does this compare to HTMX (security wise)?
- sudodevnull 1y agoSame, you control your signals and fragments. So you are responsible for proper escaping and thoughtful design.
- j13n 1y agoYou can disable all use of eval with htmx. The tradeoff is one has to write a bit more JavaScript. https://news.ycombinator.com/item?id=43650921 https://news.ycombinator.com/item?id=43650921
- sudodevnull 1y agoI have thoughts about a fully compliant CSP middleware, problem is it's per language so I'd probably only make for Go (maybe PHP & TS)
- geoka9 1y agoHashes or nonces?
- sudodevnull 1y agoHashed script content
- geoka9 1y agoThank you for doing this. Is it possible to follow the work somewhere?
- sudodevnull 1y agoNot right now. CSP in a Datastar context is mostly a red herring. If an enterprise wants it to check a box then please reach out.
- geoka9 1y agoI don't represent an enterprise; just a dev. It would make it easier to sell the idea of Datastar to clients if it was compatible with strict CSP.
- sudodevnull 1y agoThat's the nature of anything that does this kind of work. React, Svelte, Solid. Alpine has a CSP version but it does so little that I recommend you just accept being a Web1 MPA basic site. I have ideas around ways around this but it's a per language template middleware.
- dpc_01234 1y agoIs there anything I could read detailed explanation of issue, in particular w.r.t datastar?
- jazoom 1y agoAlpine CSP version works fine. You just can't write JS code in strings, which one may wish to avoid anyway. I also didn't have a problem with CSP and HTMX. Nor with SvelteKit. I'm not sure why you think these are all equivalent to DataStar's hard requirement on unsafe-eval. FYI, this is the reason I didn't try out DataStar.
- pie_flavor 1y agoSvelte only requires a CSP hole in its default config as a standalone library; SvelteKit does proper CSP by default, and if you're not using SvelteKit you can build CSP handling into whatever you are using instead. I assume the others are the same way.
- tauroid 1y agoCould you avoid eval by having a CSP mode that forces reactive expressions to only allow functions users have registered with datastar in a lookup table?
- nchmy 1y agocould you please elaborate on this?
- andersmurphy 1y agoPlease don't cargo cult CSP without understanding it. unsafe-eval constrained to function constructors without inline scripts is only a concern if you are rendering user submitted HTML (most common case I see is markdown). Regardless of your CSP configuration you should be sanitizing that user submitted HTML anyway.