Skip to content

v1.8.2 — Anti-clickjacking guard (security)

Choose a tag to compare

@colourbill-ctrl colourbill-ctrl released this 14 Jul 17:44
· 48 commits to main since this release

Security patch from an antagonistic review of chardata + profiletool.

Fixed — Clickjacking (Medium-Low)

The CSP's frame-ancestors 'none' was delivered via a <meta> tag, where — per the CSP spec — it is silently ignored (that directive, like report-uri/sandbox, is honored only in an HTTP response header). The production subpath (/var/www/profiletool/) is nginx-served outside chardata's helmet and shipped no X-Frame-Options either, so the editor could be framed for a clickjacking overlay.

Fix (defence-in-depth, ships without server access): public/noclickjack.js hides <html> by default and reveals it only when self === top; it busts out if framed and fails closed (stays hidden) if a sandboxed iframe neutralizes the bust-out. Loaded as a synchronous, same-origin classic script — deliberately not inline (script-src omits 'unsafe-inline') and not a CSP hash (Vite could minify inline bytes), served from public/ so it's copied verbatim. The legitimate chardata window.open handoff runs as self === top, so it is unaffected.

Still recommended (the real fix): a true HTTP header on the nginx location /profiletool/ block —

add_header X-Frame-Options "DENY" always;
add_header Content-Security-Policy "frame-ancestors 'none'" always;

This in-app guard is the belt-and-suspenders alongside it.