merge: restrictive CSP and narrowed asset scope (C1, C2)

Set a CSP with script-src 'self' (Tauri nonces the one inline bootstrap script),
object-src/frame-src 'none', and necessarily-permissive img/media/connect for the
user-supplied Jellyfin origin. Narrow assetProtocol $APPDATA/** -> thumbnails/**,
which is convertFileSrc's only remaining caller.

Conflict resolution: scripts/extract-traces.test.ts pinned counts summed rather
than side-picked — DR-189 and DR-198 were added independently on two branches,
so DR 187 -> 189 and total 330 -> 332. docs/traceability.md regenerated.
This commit is contained in:
2026-08-16 23:01:50 +02:00
10 changed files with 4799 additions and 4085 deletions
+15 -8
View File
@@ -1029,16 +1029,23 @@ fn set_env_if_unset(key: &str, value: &str) {
}
}
/// Downloaded media and cached thumbnails are handed to the webview as
/// `http://asset.localhost/…` URLs by `convertFileSrc`. Tauri only answers that
/// Cached thumbnails are handed to the webview as asset-protocol URLs by
/// `convertFileSrc` (`asset://localhost/…` on Linux/macOS,
/// `http://asset.localhost/…` on Windows/Android). Tauri only answers that
/// origin when the `protocol-asset` cargo feature is compiled in *and*
/// `app.security.assetProtocol.enable` is set in `tauri.conf.json`, which also
/// scopes it to `$APPDATA/**` — the storage root holding the database,
/// `downloads/` and the thumbnail cache. Both are required together: with either
/// missing the URL resolves to nothing and the webview reports
/// `NETWORK_NO_SOURCE`, which is how offline video came to fail silently.
/// `app.security.assetProtocol.enable` is set in `tauri.conf.json`. Both are
/// required together: with either missing the URL resolves to nothing and the
/// webview reports `NETWORK_NO_SOURCE`, which is how offline video came to fail
/// silently.
///
/// TRACES: UR-071 | DR-134
/// The scope is `$APPDATA/thumbnails/**`, not the storage root: downloaded media
/// moved to the loopback media server in DR-137, so `imageCache` is the only
/// remaining `convertFileSrc` caller and the database and the encrypted-token
/// fallback file — which share that root — never need to be readable by the
/// webview. Widen it only if something other than thumbnails starts resolving
/// through `convertFileSrc` again.
///
/// TRACES: UR-012, UR-071 | DR-134, DR-137, DR-198
#[cfg_attr(mobile, tauri::mobile_entry_point)]
pub fn run() {
// Initialize logger