ask for XSS protection
Costa Tsaousis (ktsaou) committed
Jan 29, 2018 at 22:11 UTC
2ebee50887027f4ed4a4c736d6aa5b32b571f020
2 files changed
+58
-4
web/dashboard.js
+13
-4
@@ -106,6 +106,7 @@ var NETDATA = window.NETDATA || {};
106
107
NETDATA.xss = {
108
enabled: (typeof netdataCheckXSS === 'undefined')?false:netdataCheckXSS,
109
+ enabled_for_data: (typeof netdataCheckXSS === 'undefined')?false:netdataCheckXSS,
110
111
string: function (s) {
112
if (typeof s === 'string' || typeof s === 'number' || typeof s === 'boolean')
@@ -168,15 +169,23 @@ var NETDATA = window.NETDATA || {};
169
170
checkOptional: function(name, obj, ignore_regex) {
171
if(this.enabled === true) {
171
- // console.log('XSS: checking "' + name + '"...');
172
+ console.log('XSS: checking optional "' + name + '"...');
173
return this.object(name, obj, ignore_regex);
174
}
175
return obj;
176
},
177
178
checkAlways: function(name, obj, ignore_regex) {
178
- // console.log('XSS: checking "' + name + '"...');
179
+ console.log('XSS: checking always "' + name + '"...');
180
return this.object(name, obj, ignore_regex);
181
+ },
182
+
183
+ checkData: function(name, obj, ignore_regex) {
184
+ if(this.enabled_for_data === true) {
185
+ console.log('XSS: checking data "' + name + '"...');
186
+ return this.object(name, obj, ignore_regex);
187
+ }
188
+ return obj;
189
}
190
};
191
@@ -4977,7 +4986,7 @@ var NETDATA = window.NETDATA || {};
4986
var data = this.getSnapshotData(key);
4987
if (data !== null) {
4988
ok = true;
4980
- data = NETDATA.xss.checkAlways('/api/v1/data', data, this.library.xssRegexIgnore);
4989
+ data = NETDATA.xss.checkData('/api/v1/data', data, this.library.xssRegexIgnore);
4990
this.updateChartWithData(data);
4991
}
4992
else {
@@ -5009,7 +5018,7 @@ var NETDATA = window.NETDATA || {};
5018
xhrFields: { withCredentials: true } // required for the cookie
5019
})
5020
.done(function(data) {
5012
- data = NETDATA.xss.checkOptional('/api/v1/data', data, that.library.xssRegexIgnore);
5021
+ data = NETDATA.xss.checkData('/api/v1/data', data, that.library.xssRegexIgnore);
5022
5023
that.xhr = undefined;
5024
that.retries_on_data_failures = 0;
web/index.html
+45
@@ -3206,6 +3206,7 @@
3206
$('#loadSnapshotImport').addClass('disabled');
3207
3208
if(tmpSnapshotData === null) {
3209
+ loadSnapshotPreflightEmpty();
3210
loadSnapshotModalLog('danger', 'no data have been loaded');
3211
return;
3212
}
@@ -3272,7 +3273,11 @@
3273
urlOptions.highlight = false;
3274
}
3275
3276
+ netdataCheckXSS = false; // disable the modal - this does not affect XSS checks, since dashboard.js is already loaded
3277
+ NETDATA.xss.enabled = true; // we should not do any remote requests, but if we do, check them
3278
+ NETDATA.xss.enabled_for_data = true; // check also snapshot data - that have been excluded from the initial check, due to compression
3279
initializeDynamicDashboard();
3280
+ loadSnapshotPreflightEmpty();
3281
});
3282
});
3283
};
@@ -4318,6 +4323,13 @@
4323
NETDATA.globalPanAndZoom.setMaster(NETDATA.options.targets[0], netdataSnapshotData.after_ms, netdataSnapshotData.before_ms);
4324
}
4325
4326
+ if(typeof netdataCheckXSS !== 'undefined' && netdataCheckXSS === true) {
4327
+ setTimeout(function() {
4328
+ document.getElementById('netdataXssModalServer').innerText = netdataServer;
4329
+ $('#xssModal').modal('show');
4330
+ }, 1000);
4331
+ }
4332
+
4333
// var netdataEnded = performance.now();
4334
// console.log('start up time: ' + (netdataEnded - netdataStarted).toString() + ' ms');
4335
}
@@ -4579,6 +4591,39 @@
4591
</div>
4592
</div>
4593
4594
+ <div class="modal fade" id="xssModal" tabindex="-1" role="dialog" aria-labelledby="xssModalLabel">
4595
+ <div class="modal-dialog modal-lg" role="document">
4596
+ <div class="modal-content">
4597
+ <div class="modal-header">
4598
+ <button type="button" class="close" data-dismiss="modal" aria-label="Close"><span aria-hidden="true">×</span></button>
4599
+ <h4 class="modal-title" id="xssModalLabel">XSS Protection</h4>
4600
+ </div>
4601
+ <div class="modal-body">
4602
+ <p>
4603
+ This dashboard is now rendering data of server:
4604
+ </p>
4605
+ <p style="font-size: 1.25em;">
4606
+ <code id="netdataXssModalServer"></code>
4607
+ </p>
4608
+ <p>
4609
+ To protect your privacy, the dashboard is <b>checking all data transferred</b> for cross site scripting (XSS).
4610
+ This is CPU intensive, so your browser might be a bit slower.
4611
+ </p>
4612
+ <p>
4613
+ If you <b>trust</b> the remote server, you can disable XSS protection, to speed it up.
4614
+ <br/>
4615
+ If you <b>don't trust</b> the remote server, you better keep it on. The dashboard will be a bit slower,
4616
+ but better be safe, than sorry...
4617
+ </p>
4618
+ </div>
4619
+ <div class="modal-footer">
4620
+ <a href="#" onclick="NETDATA.xss.enabled = true; NETDATA.xss.enabled_for_data = true; return false;" type="button" class="btn btn-success" data-dismiss="modal">Keep protecting me</a>
4621
+ <a href="#" onclick="NETDATA.xss.enabled = false; NETDATA.xss.enabled_for_data = false; return false;" type="button" class="btn btn-danger" data-dismiss="modal">I don't need this, the server is mine</a>
4622
+ </div>
4623
+ </div>
4624
+ </div>
4625
+ </div>
4626
+
4627
<div class="modal fade" id="printPreflightModal" tabindex="-1" role="dialog" aria-labelledby="printPreflightModalLabel">
4628
<div class="modal-dialog modal-lg" role="document">
4629
<div class="modal-content">