merge: restrictive CSP and narrowed asset scope (C1, C2)
Set a CSP with script-src 'self' (Tauri nonces the one inline bootstrap script), object-src/frame-src 'none', and necessarily-permissive img/media/connect for the user-supplied Jellyfin origin. Narrow assetProtocol $APPDATA/** -> thumbnails/**, which is convertFileSrc's only remaining caller. Conflict resolution: scripts/extract-traces.test.ts pinned counts summed rather than side-picked — DR-189 and DR-198 were added independently on two branches, so DR 187 -> 189 and total 330 -> 332. docs/traceability.md regenerated.
This commit is contained in:
+15
-8
@@ -1029,16 +1029,23 @@ fn set_env_if_unset(key: &str, value: &str) {
|
||||
}
|
||||
}
|
||||
|
||||
/// Downloaded media and cached thumbnails are handed to the webview as
|
||||
/// `http://asset.localhost/…` URLs by `convertFileSrc`. Tauri only answers that
|
||||
/// Cached thumbnails are handed to the webview as asset-protocol URLs by
|
||||
/// `convertFileSrc` (`asset://localhost/…` on Linux/macOS,
|
||||
/// `http://asset.localhost/…` on Windows/Android). Tauri only answers that
|
||||
/// origin when the `protocol-asset` cargo feature is compiled in *and*
|
||||
/// `app.security.assetProtocol.enable` is set in `tauri.conf.json`, which also
|
||||
/// scopes it to `$APPDATA/**` — the storage root holding the database,
|
||||
/// `downloads/` and the thumbnail cache. Both are required together: with either
|
||||
/// missing the URL resolves to nothing and the webview reports
|
||||
/// `NETWORK_NO_SOURCE`, which is how offline video came to fail silently.
|
||||
/// `app.security.assetProtocol.enable` is set in `tauri.conf.json`. Both are
|
||||
/// required together: with either missing the URL resolves to nothing and the
|
||||
/// webview reports `NETWORK_NO_SOURCE`, which is how offline video came to fail
|
||||
/// silently.
|
||||
///
|
||||
/// TRACES: UR-071 | DR-134
|
||||
/// The scope is `$APPDATA/thumbnails/**`, not the storage root: downloaded media
|
||||
/// moved to the loopback media server in DR-137, so `imageCache` is the only
|
||||
/// remaining `convertFileSrc` caller and the database and the encrypted-token
|
||||
/// fallback file — which share that root — never need to be readable by the
|
||||
/// webview. Widen it only if something other than thumbnails starts resolving
|
||||
/// through `convertFileSrc` again.
|
||||
///
|
||||
/// TRACES: UR-012, UR-071 | DR-134, DR-137, DR-198
|
||||
#[cfg_attr(mobile, tauri::mobile_entry_point)]
|
||||
pub fn run() {
|
||||
// Initialize logger
|
||||
|
||||
Reference in New Issue
Block a user