v0.3.1: Merge pull request #4 from SimCubeLtd/fix/inline-script-csp
What's Changed
- fix: let accepted inline scripts actually run by @prom3theu5 in #4
Full Changelog: v0.3.0...v0.3.1
Highlights
A fix for 0.3.0. --allow-safe-handlers accepted an inline on* handler at upload while the
served CSP still said script-src 'none', so the handler was stored and never ran.
That made the flag ineffective for the case it exists to support. In the async-CSS idiom
<link rel="stylesheet" media="print" onload="this.media='all'"> the handler is the media swap,
so with it blocked the stylesheet stayed print-only and --allow-font-links rendered no font
either, despite its CSP being correct. <noscript> does not cover it: that only renders when
scripting is disabled, and CSP-blocked scripting still counts as enabled.
--allow-inline-scripts/KERYX_ALLOW_INLINE_SCRIPTSserves drafts with
script-src 'unsafe-inline'. One keyword covers inline<script>,on*handlers and
javascript:URLs alike; upload validation is what keeps the last two in check.connect-src
stays'none'either way, since a draft is a document rather than a client for something else.
Off by default, so the strict posture is unchanged unless asked for.keryx uploadnow warns when a document carries inline scripts but the target server will not
execute them, instead of leaving it to be found in the browser console.
Note on what the flag costs: 'unsafe-inline' means any script in an uploaded document executes
when someone opens that draft, including anything that got past upload validation. That suits the
single-machine and trusted-LAN deployment Keryx targets. For a wider audience, hash-pinning the
stored scripts is the tighter option and the immutable-version model makes it straightforward.
Upgrading from 0.3.0 needs no data migration. Restart keryx serve with the flag to let existing
drafts run their scripts.
Install
Binaries are attached below for three targets. If yours is not one of them, build from source. The
release archives also include the README, licence, and ready-made Keryx agent skills.
| Platform | Asset |
|---|---|
| Linux, x86-64 (glibc 2.35+) | keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz |
| macOS, Apple Silicon | keryx-0.3.1-aarch64-apple-darwin.tar.gz |
| Windows, x86-64 | keryx-0.3.1-x86_64-pc-windows-msvc.zip |
Linux (x86-64)
gh release download v0.3.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz*'
sha256sum -c keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz
sudo install -m755 keryx-0.3.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --versionFor a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your
PATH.
macOS (Apple Silicon)
gh release download v0.3.1 --repo SimCubeLtd/keryx \
--pattern 'keryx-0.3.1-aarch64-apple-darwin.tar.gz*'
shasum -a 256 -c keryx-0.3.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.3.1-aarch64-apple-darwin.tar.gz
sudo install -m755 keryx-0.3.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --versionThe binary is not code-signed or notarised. Downloading through a browser may attach a
quarantine flag and cause Gatekeeper to refuse it; clear that flag once with:
xattr -d com.apple.quarantine /usr/local/bin/keryxIntel Macs: no binary is published. Build from source, or run the Apple Silicon build under
Rosetta 2. Rosetta is unsupported for this release and untested.
Windows (x86-64)
In PowerShell:
gh release download v0.3.1 --repo SimCubeLtd/keryx `
--pattern 'keryx-0.3.1-x86_64-pc-windows-msvc.zip*'
# Compare against the published checksum
Get-FileHash keryx-0.3.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.3.1-x86_64-pc-windows-msvc.zip.sha256
Expand-Archive keryx-0.3.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs
$dir = "$env:LOCALAPPDATA\Programs\keryx-0.3.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')Open a new terminal, then run keryx --version.
The executable is unsigned, so SmartScreen may warn on first run. Nothing here needs
administrator rights.
Build from source (any platform)
Install the Rust nightly toolchain, then:
rustup toolchain install nightly --profile minimal
git clone --branch v0.3.1 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --versionOr install the tagged release straight into ~/.cargo/bin:
cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
--tag v0.3.1 --locked keryx--locked uses the exact dependency versions in the committed Cargo.lock.