This repository was archived by the owner on Aug 29, 2025. It is now read-only.

disable nodeintegration - #453

Merged
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration
Jun 6, 2018
Merged

disable nodeintegration#453
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration

Conversation

@n-riesco

Copy link
Copy Markdown
Contributor

The main purpose of this PR is to disable nodeIntegration and strengthen the security measures in Falcon's frontend. To achieve this, I had to refactor some of the login code (so I took the opportunity to fix#260).

I've also included 2 other small fixes:


@tarzzz could you review this PR, please?

@scjody are you OK with the changes in 6100bba and f362921 ? With these changes, we send the cookies db-connector-auth-enabled, db-connector-client-id and db-connector-user over HTTP.

@kndungu I think you'll be interested in reviewing the following commits (related to security in an electron app):

n-riesco added 11 commits May 31, 2018 16:42
* This will help get rid of `shell.openExternal` in the frontend.
* Remove extra slash and ensure an absolute path is returned
* Replace call to `shell.openExternal` with an `<a>` tag.
* Don't use /datacache to save CSV files locally, because:
- it's unnecessary,
- and `<a>` can't be used to open `file://` URLs.
* Convert CSV file to data URL.
* Capture requests to open a data URL and show native a save dialog
instead.
* Ensure the cookie db-connector-user is also passed to HTTP
connections.
* Trigger the reload of the web app when the authorisation popup is
closed.
Fixes#260
* Disables nodeIntegration by moving all the use of electron's API in
the frontend to the object `window.$falcon` (that is setup inside the
preload script).
Closes#438

@scjodyscjody left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be clear: is the db-connector-auth-enabled cookie only used by the frontend to control what UI is shown? In other words I want to be sure it's not used by the backend to control whether or not auth is actually needed.

@n-riesco

Copy link
Copy Markdown
ContributorAuthor

@scjody yes, db-connector-auth-enabled works as you described.

Comment threadbackend/main.development.js Outdated
});

// prevent navigation out of HTTP_URL
// see https://electronjs.org/docs/api/web-contents#event-will-navigate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor 🐐 The link is wrong .. should link to "new-window"

Comment threadbackend/main.development.js Outdated
mainWindow.webContents.on('new-window', (event, url) => {
if (!url.startsWith(HTTP_URL)) event.preventDefault();
event.preventDefault();
shell.openExternal(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment threadapp/components/Login.react.js Outdated
constructor(props) {
super(props);
this.state = {
clientId: cookie.load('db-connector-client-id'),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

its oauth2 client id, so we can probably name it like that. DB connector in itself doesn't have a notion of client-id.

buildOauthUrl() {
const {domain} = this.state;
/* global PLOTLY_ENV */
const oauthClientId = PLOTLY_ENV.OAUTH2_CLIENT_ID;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to get rid of this.. #Cleanup.. :)

Comment threadbackend/preload.js
}
},
...propertyOptions
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good idea to only expose the functionality we need, but would be great to check this with both electron and browser / onprem.. !!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tarzzz
This change only affects to the electron app.
What checks do you have in mind?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change only affects to the electron app.

Yep, I noted it now. Only electron-app testing then (which I can see you have already done)..

@tarzzztarzzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.. Some minor comments and 💃 after testing..

Thanks for the cleanup .. !!

* Renamed cookie `db-connector-client-id` to
`db-connector-oauth2-client-id`.
@n-riesco
n-riescoforce-pushed the security/disable-nodeintegration branch from e7ea62d to 0ee49a2CompareJune 6, 2018 18:13
@n-riesco

Copy link
Copy Markdown
ContributorAuthor

I've checked login to Plotly Cloud works in the desktop and web apps.

@n-riesco
n-riesco merged commit 27f04fd into masterJun 6, 2018
@n-riesco
n-riesco deleted the security/disable-nodeintegration branch June 6, 2018 21:41
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauth redirection broken in web app

3 participants

@n-riesco@scjody@tarzzz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
This repository was archived by the owner on Aug 29, 2025. It is now read-only.

disable nodeintegration - #453

Merged
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration
Jun 6, 2018
Merged

disable nodeintegration#453
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration

Conversation

@n-riesco

Copy link
Copy Markdown
Contributor

The main purpose of this PR is to disable nodeIntegration and strengthen the security measures in Falcon's frontend. To achieve this, I had to refactor some of the login code (so I took the opportunity to fix#260).

I've also included 2 other small fixes:


@tarzzz could you review this PR, please?

@scjody are you OK with the changes in 6100bba and f362921 ? With these changes, we send the cookies db-connector-auth-enabled, db-connector-client-id and db-connector-user over HTTP.

@kndungu I think you'll be interested in reviewing the following commits (related to security in an electron app):

n-riesco added 11 commits May 31, 2018 16:42
* This will help get rid of `shell.openExternal` in the frontend.
* Remove extra slash and ensure an absolute path is returned
* Replace call to `shell.openExternal` with an `<a>` tag.
* Don't use /datacache to save CSV files locally, because:
- it's unnecessary,
- and `<a>` can't be used to open `file://` URLs.
* Convert CSV file to data URL.
* Capture requests to open a data URL and show native a save dialog
instead.
* Ensure the cookie db-connector-user is also passed to HTTP
connections.
* Trigger the reload of the web app when the authorisation popup is
closed.
Fixes#260
* Disables nodeIntegration by moving all the use of electron's API in
the frontend to the object `window.$falcon` (that is setup inside the
preload script).
Closes#438

@scjodyscjody left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be clear: is the db-connector-auth-enabled cookie only used by the frontend to control what UI is shown? In other words I want to be sure it's not used by the backend to control whether or not auth is actually needed.

@n-riesco

Copy link
Copy Markdown
ContributorAuthor

@scjody yes, db-connector-auth-enabled works as you described.

Comment threadbackend/main.development.js Outdated
});

// prevent navigation out of HTTP_URL
// see https://electronjs.org/docs/api/web-contents#event-will-navigate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor 🐐 The link is wrong .. should link to "new-window"

Comment threadbackend/main.development.js Outdated
mainWindow.webContents.on('new-window', (event, url) => {
if (!url.startsWith(HTTP_URL)) event.preventDefault();
event.preventDefault();
shell.openExternal(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment threadapp/components/Login.react.js Outdated
constructor(props) {
super(props);
this.state = {
clientId: cookie.load('db-connector-client-id'),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

its oauth2 client id, so we can probably name it like that. DB connector in itself doesn't have a notion of client-id.

buildOauthUrl() {
const {domain} = this.state;
/* global PLOTLY_ENV */
const oauthClientId = PLOTLY_ENV.OAUTH2_CLIENT_ID;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to get rid of this.. #Cleanup.. :)

Comment threadbackend/preload.js
}
},
...propertyOptions
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good idea to only expose the functionality we need, but would be great to check this with both electron and browser / onprem.. !!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tarzzz
This change only affects to the electron app.
What checks do you have in mind?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change only affects to the electron app.

Yep, I noted it now. Only electron-app testing then (which I can see you have already done)..

@tarzzztarzzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.. Some minor comments and 💃 after testing..

Thanks for the cleanup .. !!

* Renamed cookie `db-connector-client-id` to
`db-connector-oauth2-client-id`.
@n-riesco
n-riescoforce-pushed the security/disable-nodeintegration branch from e7ea62d to 0ee49a2CompareJune 6, 2018 18:13
@n-riesco

Copy link
Copy Markdown
ContributorAuthor

I've checked login to Plotly Cloud works in the desktop and web apps.

@n-riesco
n-riesco merged commit 27f04fd into masterJun 6, 2018
@n-riesco
n-riesco deleted the security/disable-nodeintegration branch June 6, 2018 21:41
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauth redirection broken in web app

3 participants

@n-riesco@scjody@tarzzz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 29, 2025. It is now read-only.

disable nodeintegration - #453

Merged
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration
Jun 6, 2018
Merged

disable nodeintegration#453
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration

Conversation

@n-riesco

Copy link
Copy Markdown
Contributor

The main purpose of this PR is to disable nodeIntegration and strengthen the security measures in Falcon's frontend. To achieve this, I had to refactor some of the login code (so I took the opportunity to fix#260).

I've also included 2 other small fixes:


@tarzzz could you review this PR, please?

@scjody are you OK with the changes in 6100bba and f362921 ? With these changes, we send the cookies db-connector-auth-enabled, db-connector-client-id and db-connector-user over HTTP.

@kndungu I think you'll be interested in reviewing the following commits (related to security in an electron app):

n-riesco added 11 commits May 31, 2018 16:42
* This will help get rid of `shell.openExternal` in the frontend.
* Remove extra slash and ensure an absolute path is returned
* Replace call to `shell.openExternal` with an `<a>` tag.
* Don't use /datacache to save CSV files locally, because:
- it's unnecessary,
- and `<a>` can't be used to open `file://` URLs.
* Convert CSV file to data URL.
* Capture requests to open a data URL and show native a save dialog
instead.
* Ensure the cookie db-connector-user is also passed to HTTP
connections.
* Trigger the reload of the web app when the authorisation popup is
closed.
Fixes#260
* Disables nodeIntegration by moving all the use of electron's API in
the frontend to the object `window.$falcon` (that is setup inside the
preload script).
Closes#438

@scjodyscjody left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be clear: is the db-connector-auth-enabled cookie only used by the frontend to control what UI is shown? In other words I want to be sure it's not used by the backend to control whether or not auth is actually needed.

@n-riesco

Copy link
Copy Markdown
ContributorAuthor

@scjody yes, db-connector-auth-enabled works as you described.

Comment threadbackend/main.development.js Outdated
});

// prevent navigation out of HTTP_URL
// see https://electronjs.org/docs/api/web-contents#event-will-navigate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor 🐐 The link is wrong .. should link to "new-window"

Comment threadbackend/main.development.js Outdated
mainWindow.webContents.on('new-window', (event, url) => {
if (!url.startsWith(HTTP_URL)) event.preventDefault();
event.preventDefault();
shell.openExternal(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment threadapp/components/Login.react.js Outdated
constructor(props) {
super(props);
this.state = {
clientId: cookie.load('db-connector-client-id'),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

its oauth2 client id, so we can probably name it like that. DB connector in itself doesn't have a notion of client-id.

buildOauthUrl() {
const {domain} = this.state;
/* global PLOTLY_ENV */
const oauthClientId = PLOTLY_ENV.OAUTH2_CLIENT_ID;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to get rid of this.. #Cleanup.. :)

Comment threadbackend/preload.js
}
},
...propertyOptions
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good idea to only expose the functionality we need, but would be great to check this with both electron and browser / onprem.. !!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tarzzz
This change only affects to the electron app.
What checks do you have in mind?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change only affects to the electron app.

Yep, I noted it now. Only electron-app testing then (which I can see you have already done)..

@tarzzztarzzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.. Some minor comments and 💃 after testing..

Thanks for the cleanup .. !!

* Renamed cookie `db-connector-client-id` to
`db-connector-oauth2-client-id`.
@n-riesco
n-riescoforce-pushed the security/disable-nodeintegration branch from e7ea62d to 0ee49a2CompareJune 6, 2018 18:13
@n-riesco

Copy link
Copy Markdown
ContributorAuthor

I've checked login to Plotly Cloud works in the desktop and web apps.

@n-riesco
n-riesco merged commit 27f04fd into masterJun 6, 2018
@n-riesco
n-riesco deleted the security/disable-nodeintegration branch June 6, 2018 21:41
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauth redirection broken in web app

3 participants

@n-riesco@scjody@tarzzz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 29, 2025. It is now read-only.

disable nodeintegration - #453

Merged
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration
Jun 6, 2018
Merged

disable nodeintegration#453
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration

Conversation

@n-riesco

Copy link
Copy Markdown
Contributor

The main purpose of this PR is to disable nodeIntegration and strengthen the security measures in Falcon's frontend. To achieve this, I had to refactor some of the login code (so I took the opportunity to fix#260).

I've also included 2 other small fixes:


@tarzzz could you review this PR, please?

@scjody are you OK with the changes in 6100bba and f362921 ? With these changes, we send the cookies db-connector-auth-enabled, db-connector-client-id and db-connector-user over HTTP.

@kndungu I think you'll be interested in reviewing the following commits (related to security in an electron app):

n-riesco added 11 commits May 31, 2018 16:42
* This will help get rid of `shell.openExternal` in the frontend.
* Remove extra slash and ensure an absolute path is returned
* Replace call to `shell.openExternal` with an `<a>` tag.
* Don't use /datacache to save CSV files locally, because:
- it's unnecessary,
- and `<a>` can't be used to open `file://` URLs.
* Convert CSV file to data URL.
* Capture requests to open a data URL and show native a save dialog
instead.
* Ensure the cookie db-connector-user is also passed to HTTP
connections.
* Trigger the reload of the web app when the authorisation popup is
closed.
Fixes#260
* Disables nodeIntegration by moving all the use of electron's API in
the frontend to the object `window.$falcon` (that is setup inside the
preload script).
Closes#438

@scjodyscjody left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be clear: is the db-connector-auth-enabled cookie only used by the frontend to control what UI is shown? In other words I want to be sure it's not used by the backend to control whether or not auth is actually needed.

@n-riesco

Copy link
Copy Markdown
ContributorAuthor

@scjody yes, db-connector-auth-enabled works as you described.

Comment threadbackend/main.development.js Outdated
});

// prevent navigation out of HTTP_URL
// see https://electronjs.org/docs/api/web-contents#event-will-navigate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor 🐐 The link is wrong .. should link to "new-window"

Comment threadbackend/main.development.js Outdated
mainWindow.webContents.on('new-window', (event, url) => {
if (!url.startsWith(HTTP_URL)) event.preventDefault();
event.preventDefault();
shell.openExternal(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment threadapp/components/Login.react.js Outdated
constructor(props) {
super(props);
this.state = {
clientId: cookie.load('db-connector-client-id'),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

its oauth2 client id, so we can probably name it like that. DB connector in itself doesn't have a notion of client-id.

buildOauthUrl() {
const {domain} = this.state;
/* global PLOTLY_ENV */
const oauthClientId = PLOTLY_ENV.OAUTH2_CLIENT_ID;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to get rid of this.. #Cleanup.. :)

Comment threadbackend/preload.js
}
},
...propertyOptions
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good idea to only expose the functionality we need, but would be great to check this with both electron and browser / onprem.. !!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tarzzz
This change only affects to the electron app.
What checks do you have in mind?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change only affects to the electron app.

Yep, I noted it now. Only electron-app testing then (which I can see you have already done)..

@tarzzztarzzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.. Some minor comments and 💃 after testing..

Thanks for the cleanup .. !!

* Renamed cookie `db-connector-client-id` to
`db-connector-oauth2-client-id`.
@n-riesco
n-riescoforce-pushed the security/disable-nodeintegration branch from e7ea62d to 0ee49a2CompareJune 6, 2018 18:13
@n-riesco

Copy link
Copy Markdown
ContributorAuthor

I've checked login to Plotly Cloud works in the desktop and web apps.

@n-riesco
n-riesco merged commit 27f04fd into masterJun 6, 2018
@n-riesco
n-riesco deleted the security/disable-nodeintegration branch June 6, 2018 21:41
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauth redirection broken in web app

3 participants

@n-riesco@scjody@tarzzz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
This repository was archived by the owner on Aug 29, 2025. It is now read-only.

disable nodeintegration - #453

Merged
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration
Jun 6, 2018
Merged

disable nodeintegration#453
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration

Conversation

@n-riesco

Copy link
Copy Markdown
Contributor

The main purpose of this PR is to disable nodeIntegration and strengthen the security measures in Falcon's frontend. To achieve this, I had to refactor some of the login code (so I took the opportunity to fix#260).

I've also included 2 other small fixes:


@tarzzz could you review this PR, please?

@scjody are you OK with the changes in 6100bba and f362921 ? With these changes, we send the cookies db-connector-auth-enabled, db-connector-client-id and db-connector-user over HTTP.

@kndungu I think you'll be interested in reviewing the following commits (related to security in an electron app):

n-riesco added 11 commits May 31, 2018 16:42
* This will help get rid of `shell.openExternal` in the frontend.
* Remove extra slash and ensure an absolute path is returned
* Replace call to `shell.openExternal` with an `<a>` tag.
* Don't use /datacache to save CSV files locally, because:
- it's unnecessary,
- and `<a>` can't be used to open `file://` URLs.
* Convert CSV file to data URL.
* Capture requests to open a data URL and show native a save dialog
instead.
* Ensure the cookie db-connector-user is also passed to HTTP
connections.
* Trigger the reload of the web app when the authorisation popup is
closed.
Fixes#260
* Disables nodeIntegration by moving all the use of electron's API in
the frontend to the object `window.$falcon` (that is setup inside the
preload script).
Closes#438

@scjodyscjody left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be clear: is the db-connector-auth-enabled cookie only used by the frontend to control what UI is shown? In other words I want to be sure it's not used by the backend to control whether or not auth is actually needed.

@n-riesco

Copy link
Copy Markdown
ContributorAuthor

@scjody yes, db-connector-auth-enabled works as you described.

Comment threadbackend/main.development.js Outdated
});

// prevent navigation out of HTTP_URL
// see https://electronjs.org/docs/api/web-contents#event-will-navigate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor 🐐 The link is wrong .. should link to "new-window"

Comment threadbackend/main.development.js Outdated
mainWindow.webContents.on('new-window', (event, url) => {
if (!url.startsWith(HTTP_URL)) event.preventDefault();
event.preventDefault();
shell.openExternal(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment threadapp/components/Login.react.js Outdated
constructor(props) {
super(props);
this.state = {
clientId: cookie.load('db-connector-client-id'),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

its oauth2 client id, so we can probably name it like that. DB connector in itself doesn't have a notion of client-id.

buildOauthUrl() {
const {domain} = this.state;
/* global PLOTLY_ENV */
const oauthClientId = PLOTLY_ENV.OAUTH2_CLIENT_ID;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to get rid of this.. #Cleanup.. :)

Comment threadbackend/preload.js
}
},
...propertyOptions
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good idea to only expose the functionality we need, but would be great to check this with both electron and browser / onprem.. !!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tarzzz
This change only affects to the electron app.
What checks do you have in mind?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change only affects to the electron app.

Yep, I noted it now. Only electron-app testing then (which I can see you have already done)..

@tarzzztarzzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.. Some minor comments and 💃 after testing..

Thanks for the cleanup .. !!

* Renamed cookie `db-connector-client-id` to
`db-connector-oauth2-client-id`.
@n-riesco
n-riescoforce-pushed the security/disable-nodeintegration branch from e7ea62d to 0ee49a2CompareJune 6, 2018 18:13
@n-riesco

Copy link
Copy Markdown
ContributorAuthor

I've checked login to Plotly Cloud works in the desktop and web apps.

@n-riesco
n-riesco merged commit 27f04fd into masterJun 6, 2018
@n-riesco
n-riesco deleted the security/disable-nodeintegration branch June 6, 2018 21:41
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauth redirection broken in web app

3 participants

@n-riesco@scjody@tarzzz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 29, 2025. It is now read-only.

disable nodeintegration - #453

Merged
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration
Jun 6, 2018
Merged

disable nodeintegration#453
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration

Conversation

@n-riesco

Copy link
Copy Markdown
Contributor

The main purpose of this PR is to disable nodeIntegration and strengthen the security measures in Falcon's frontend. To achieve this, I had to refactor some of the login code (so I took the opportunity to fix#260).

I've also included 2 other small fixes:


@tarzzz could you review this PR, please?

@scjody are you OK with the changes in 6100bba and f362921 ? With these changes, we send the cookies db-connector-auth-enabled, db-connector-client-id and db-connector-user over HTTP.

@kndungu I think you'll be interested in reviewing the following commits (related to security in an electron app):

n-riesco added 11 commits May 31, 2018 16:42
* This will help get rid of `shell.openExternal` in the frontend.
* Remove extra slash and ensure an absolute path is returned
* Replace call to `shell.openExternal` with an `<a>` tag.
* Don't use /datacache to save CSV files locally, because:
- it's unnecessary,
- and `<a>` can't be used to open `file://` URLs.
* Convert CSV file to data URL.
* Capture requests to open a data URL and show native a save dialog
instead.
* Ensure the cookie db-connector-user is also passed to HTTP
connections.
* Trigger the reload of the web app when the authorisation popup is
closed.
Fixes#260
* Disables nodeIntegration by moving all the use of electron's API in
the frontend to the object `window.$falcon` (that is setup inside the
preload script).
Closes#438

@scjodyscjody left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be clear: is the db-connector-auth-enabled cookie only used by the frontend to control what UI is shown? In other words I want to be sure it's not used by the backend to control whether or not auth is actually needed.

@n-riesco

Copy link
Copy Markdown
ContributorAuthor

@scjody yes, db-connector-auth-enabled works as you described.

Comment threadbackend/main.development.js Outdated
});

// prevent navigation out of HTTP_URL
// see https://electronjs.org/docs/api/web-contents#event-will-navigate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor 🐐 The link is wrong .. should link to "new-window"

Comment threadbackend/main.development.js Outdated
mainWindow.webContents.on('new-window', (event, url) => {
if (!url.startsWith(HTTP_URL)) event.preventDefault();
event.preventDefault();
shell.openExternal(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment threadapp/components/Login.react.js Outdated
constructor(props) {
super(props);
this.state = {
clientId: cookie.load('db-connector-client-id'),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

its oauth2 client id, so we can probably name it like that. DB connector in itself doesn't have a notion of client-id.

buildOauthUrl() {
const {domain} = this.state;
/* global PLOTLY_ENV */
const oauthClientId = PLOTLY_ENV.OAUTH2_CLIENT_ID;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to get rid of this.. #Cleanup.. :)

Comment threadbackend/preload.js
}
},
...propertyOptions
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good idea to only expose the functionality we need, but would be great to check this with both electron and browser / onprem.. !!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tarzzz
This change only affects to the electron app.
What checks do you have in mind?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change only affects to the electron app.

Yep, I noted it now. Only electron-app testing then (which I can see you have already done)..

@tarzzztarzzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.. Some minor comments and 💃 after testing..

Thanks for the cleanup .. !!

* Renamed cookie `db-connector-client-id` to
`db-connector-oauth2-client-id`.
@n-riesco
n-riescoforce-pushed the security/disable-nodeintegration branch from e7ea62d to 0ee49a2CompareJune 6, 2018 18:13
@n-riesco

Copy link
Copy Markdown
ContributorAuthor

I've checked login to Plotly Cloud works in the desktop and web apps.

@n-riesco
n-riesco merged commit 27f04fd into masterJun 6, 2018
@n-riesco
n-riesco deleted the security/disable-nodeintegration branch June 6, 2018 21:41
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauth redirection broken in web app

3 participants

@n-riesco@scjody@tarzzz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Aug 29, 2025. It is now read-only.

disable nodeintegration - #453

Merged
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration
Jun 6, 2018
Merged

disable nodeintegration#453
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration

Conversation

@n-riesco

Copy link
Copy Markdown
Contributor

The main purpose of this PR is to disable nodeIntegration and strengthen the security measures in Falcon's frontend. To achieve this, I had to refactor some of the login code (so I took the opportunity to fix#260).

I've also included 2 other small fixes:


@tarzzz could you review this PR, please?

@scjody are you OK with the changes in 6100bba and f362921 ? With these changes, we send the cookies db-connector-auth-enabled, db-connector-client-id and db-connector-user over HTTP.

@kndungu I think you'll be interested in reviewing the following commits (related to security in an electron app):

n-riesco added 11 commits May 31, 2018 16:42
* This will help get rid of `shell.openExternal` in the frontend.
* Remove extra slash and ensure an absolute path is returned
* Replace call to `shell.openExternal` with an `<a>` tag.
* Don't use /datacache to save CSV files locally, because:
- it's unnecessary,
- and `<a>` can't be used to open `file://` URLs.
* Convert CSV file to data URL.
* Capture requests to open a data URL and show native a save dialog
instead.
* Ensure the cookie db-connector-user is also passed to HTTP
connections.
* Trigger the reload of the web app when the authorisation popup is
closed.
Fixes#260
* Disables nodeIntegration by moving all the use of electron's API in
the frontend to the object `window.$falcon` (that is setup inside the
preload script).
Closes#438

@scjodyscjody left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be clear: is the db-connector-auth-enabled cookie only used by the frontend to control what UI is shown? In other words I want to be sure it's not used by the backend to control whether or not auth is actually needed.

@n-riesco

Copy link
Copy Markdown
ContributorAuthor

@scjody yes, db-connector-auth-enabled works as you described.

Comment threadbackend/main.development.js Outdated
});

// prevent navigation out of HTTP_URL
// see https://electronjs.org/docs/api/web-contents#event-will-navigate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor 🐐 The link is wrong .. should link to "new-window"

Comment threadbackend/main.development.js Outdated
mainWindow.webContents.on('new-window', (event, url) => {
if (!url.startsWith(HTTP_URL)) event.preventDefault();
event.preventDefault();
shell.openExternal(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment threadapp/components/Login.react.js Outdated
constructor(props) {
super(props);
this.state = {
clientId: cookie.load('db-connector-client-id'),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

its oauth2 client id, so we can probably name it like that. DB connector in itself doesn't have a notion of client-id.

buildOauthUrl() {
const {domain} = this.state;
/* global PLOTLY_ENV */
const oauthClientId = PLOTLY_ENV.OAUTH2_CLIENT_ID;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to get rid of this.. #Cleanup.. :)

Comment threadbackend/preload.js
}
},
...propertyOptions
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good idea to only expose the functionality we need, but would be great to check this with both electron and browser / onprem.. !!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tarzzz
This change only affects to the electron app.
What checks do you have in mind?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change only affects to the electron app.

Yep, I noted it now. Only electron-app testing then (which I can see you have already done)..

@tarzzztarzzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.. Some minor comments and 💃 after testing..

Thanks for the cleanup .. !!

* Renamed cookie `db-connector-client-id` to
`db-connector-oauth2-client-id`.
@n-riesco
n-riescoforce-pushed the security/disable-nodeintegration branch from e7ea62d to 0ee49a2CompareJune 6, 2018 18:13
@n-riesco

Copy link
Copy Markdown
ContributorAuthor

I've checked login to Plotly Cloud works in the desktop and web apps.

@n-riesco
n-riesco merged commit 27f04fd into masterJun 6, 2018
@n-riesco
n-riesco deleted the security/disable-nodeintegration branch June 6, 2018 21:41
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauth redirection broken in web app

3 participants

@n-riesco@scjody@tarzzz
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
This repository was archived by the owner on Aug 29, 2025. It is now read-only.

disable nodeintegration - #453

Merged
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration
Jun 6, 2018
Merged

disable nodeintegration#453
n-riesco merged 13 commits into
masterfrom
security/disable-nodeintegration

Conversation

@n-riesco

Copy link
Copy Markdown
Contributor

The main purpose of this PR is to disable nodeIntegration and strengthen the security measures in Falcon's frontend. To achieve this, I had to refactor some of the login code (so I took the opportunity to fix#260).

I've also included 2 other small fixes:


@tarzzz could you review this PR, please?

@scjody are you OK with the changes in 6100bba and f362921 ? With these changes, we send the cookies db-connector-auth-enabled, db-connector-client-id and db-connector-user over HTTP.

@kndungu I think you'll be interested in reviewing the following commits (related to security in an electron app):

n-riesco added 11 commits May 31, 2018 16:42
* This will help get rid of `shell.openExternal` in the frontend.
* Remove extra slash and ensure an absolute path is returned
* Replace call to `shell.openExternal` with an `<a>` tag.
* Don't use /datacache to save CSV files locally, because:
- it's unnecessary,
- and `<a>` can't be used to open `file://` URLs.
* Convert CSV file to data URL.
* Capture requests to open a data URL and show native a save dialog
instead.
* Ensure the cookie db-connector-user is also passed to HTTP
connections.
* Trigger the reload of the web app when the authorisation popup is
closed.
Fixes#260
* Disables nodeIntegration by moving all the use of electron's API in
the frontend to the object `window.$falcon` (that is setup inside the
preload script).
Closes#438

@scjodyscjody left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To be clear: is the db-connector-auth-enabled cookie only used by the frontend to control what UI is shown? In other words I want to be sure it's not used by the backend to control whether or not auth is actually needed.

@n-riesco

Copy link
Copy Markdown
ContributorAuthor

@scjody yes, db-connector-auth-enabled works as you described.

Comment threadbackend/main.development.js Outdated
});

// prevent navigation out of HTTP_URL
// see https://electronjs.org/docs/api/web-contents#event-will-navigate

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor 🐐 The link is wrong .. should link to "new-window"

Comment threadbackend/main.development.js Outdated
mainWindow.webContents.on('new-window', (event, url) => {
if (!url.startsWith(HTTP_URL)) event.preventDefault();
event.preventDefault();
shell.openExternal(url);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Comment threadapp/components/Login.react.js Outdated
constructor(props) {
super(props);
this.state = {
clientId: cookie.load('db-connector-client-id'),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

its oauth2 client id, so we can probably name it like that. DB connector in itself doesn't have a notion of client-id.

buildOauthUrl() {
const {domain} = this.state;
/* global PLOTLY_ENV */
const oauthClientId = PLOTLY_ENV.OAUTH2_CLIENT_ID;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to get rid of this.. #Cleanup.. :)

Comment threadbackend/preload.js
}
},
...propertyOptions
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good idea to only expose the functionality we need, but would be great to check this with both electron and browser / onprem.. !!

Copy link
Copy Markdown
ContributorAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tarzzz
This change only affects to the electron app.
What checks do you have in mind?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This change only affects to the electron app.

Yep, I noted it now. Only electron-app testing then (which I can see you have already done)..

@tarzzztarzzz left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.. Some minor comments and 💃 after testing..

Thanks for the cleanup .. !!

* Renamed cookie `db-connector-client-id` to
`db-connector-oauth2-client-id`.
@n-riesco
n-riescoforce-pushed the security/disable-nodeintegration branch from e7ea62d to 0ee49a2CompareJune 6, 2018 18:13
@n-riesco

Copy link
Copy Markdown
ContributorAuthor

I've checked login to Plotly Cloud works in the desktop and web apps.

@n-riesco
n-riesco merged commit 27f04fd into masterJun 6, 2018
@n-riesco
n-riesco deleted the security/disable-nodeintegration branch June 6, 2018 21:41
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

oauth redirection broken in web app

3 participants

@n-riesco@scjody@tarzzz