Skip to content

v0.3.1: Merge pull request #4 from SimCubeLtd/fix/inline-script-csp

Choose a tag to compare

@prom3theu5 prom3theu5 released this 26 Aug 13:22
· 96 commits to main since this release
724a1e1

What's Changed

  • fix: let accepted inline scripts actually run by @prom3theu5 in #4

Full Changelog: v0.3.0...v0.3.1


Highlights

A fix for 0.3.0. --allow-safe-handlers accepted an inline on* handler at upload while the
served CSP still said script-src 'none', so the handler was stored and never ran.

That made the flag ineffective for the case it exists to support. In the async-CSS idiom
<link rel="stylesheet" media="print" onload="this.media='all'"> the handler is the media swap,
so with it blocked the stylesheet stayed print-only and --allow-font-links rendered no font
either, despite its CSP being correct. <noscript> does not cover it: that only renders when
scripting is disabled, and CSP-blocked scripting still counts as enabled.

  • --allow-inline-scripts / KERYX_ALLOW_INLINE_SCRIPTS serves drafts with
    script-src 'unsafe-inline'. One keyword covers inline <script>, on* handlers and
    javascript: URLs alike; upload validation is what keeps the last two in check. connect-src
    stays 'none' either way, since a draft is a document rather than a client for something else.
    Off by default, so the strict posture is unchanged unless asked for.
  • keryx upload now warns when a document carries inline scripts but the target server will not
    execute them, instead of leaving it to be found in the browser console.

Note on what the flag costs: 'unsafe-inline' means any script in an uploaded document executes
when someone opens that draft, including anything that got past upload validation. That suits the
single-machine and trusted-LAN deployment Keryx targets. For a wider audience, hash-pinning the
stored scripts is the tighter option and the immutable-version model makes it straightforward.

Upgrading from 0.3.0 needs no data migration. Restart keryx serve with the flag to let existing
drafts run their scripts.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The
release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.3.1-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.3.1-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download v0.3.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.3.1-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.3.1-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your
PATH.

macOS (Apple Silicon)

gh release download v0.3.1 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.3.1-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.3.1-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.3.1-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.3.1-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser may attach a
quarantine flag and cause Gatekeeper to refuse it; clear that flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs: no binary is published. Build from source, or run the Apple Silicon build under
Rosetta 2. Rosetta is unsupported for this release and untested.

Windows (x86-64)

In PowerShell:

gh release download v0.3.1 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.3.1-x86_64-pc-windows-msvc.zip*'

# Compare against the published checksum
Get-FileHash keryx-0.3.1-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.3.1-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.3.1-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.3.1-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen may warn on first run. Nothing here needs
administrator rights.

Build from source (any platform)

Install the Rust nightly toolchain, then:

rustup toolchain install nightly --profile minimal
git clone --branch v0.3.1 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --version

Or install the tagged release straight into ~/.cargo/bin:

cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
  --tag v0.3.1 --locked keryx

--locked uses the exact dependency versions in the committed Cargo.lock.