@cryptotaxi247 / netdata-1 / commits / 2ebee5088

ask for XSS protection

Costa Tsaousis (ktsaou) committed Jan 29, 2018 at 22:11 UTC 2ebee50887027f4ed4a4c736d6aa5b32b571f020
2 files changed +58 -4
web/dashboard.js
+13 -4
@@ -106,6 +106,7 @@ var NETDATA = window.NETDATA || {};
106
107 NETDATA.xss = {
108 enabled: (typeof netdataCheckXSS === 'undefined')?false:netdataCheckXSS,
109 + enabled_for_data: (typeof netdataCheckXSS === 'undefined')?false:netdataCheckXSS,
110
111 string: function (s) {
112 if (typeof s === 'string' || typeof s === 'number' || typeof s === 'boolean')
@@ -168,15 +169,23 @@ var NETDATA = window.NETDATA || {};
169
170 checkOptional: function(name, obj, ignore_regex) {
171 if(this.enabled === true) {
171 - // console.log('XSS: checking "' + name + '"...');
172 + console.log('XSS: checking optional "' + name + '"...');
173 return this.object(name, obj, ignore_regex);
174 }
175 return obj;
176 },
177
178 checkAlways: function(name, obj, ignore_regex) {
178 - // console.log('XSS: checking "' + name + '"...');
179 + console.log('XSS: checking always "' + name + '"...');
180 return this.object(name, obj, ignore_regex);
181 + },
182 +
183 + checkData: function(name, obj, ignore_regex) {
184 + if(this.enabled_for_data === true) {
185 + console.log('XSS: checking data "' + name + '"...');
186 + return this.object(name, obj, ignore_regex);
187 + }
188 + return obj;
189 }
190 };
191
@@ -4977,7 +4986,7 @@ var NETDATA = window.NETDATA || {};
4986 var data = this.getSnapshotData(key);
4987 if (data !== null) {
4988 ok = true;
4980 - data = NETDATA.xss.checkAlways('/api/v1/data', data, this.library.xssRegexIgnore);
4989 + data = NETDATA.xss.checkData('/api/v1/data', data, this.library.xssRegexIgnore);
4990 this.updateChartWithData(data);
4991 }
4992 else {
@@ -5009,7 +5018,7 @@ var NETDATA = window.NETDATA || {};
5018 xhrFields: { withCredentials: true } // required for the cookie
5019 })
5020 .done(function(data) {
5012 - data = NETDATA.xss.checkOptional('/api/v1/data', data, that.library.xssRegexIgnore);
5021 + data = NETDATA.xss.checkData('/api/v1/data', data, that.library.xssRegexIgnore);
5022
5023 that.xhr = undefined;
5024 that.retries_on_data_failures = 0;
web/index.html
+45
@@ -3206,6 +3206,7 @@
3206 $('#loadSnapshotImport').addClass('disabled');
3207
3208 if(tmpSnapshotData === null) {
3209 + loadSnapshotPreflightEmpty();
3210 loadSnapshotModalLog('danger', 'no data have been loaded');
3211 return;
3212 }
@@ -3272,7 +3273,11 @@
3273 urlOptions.highlight = false;
3274 }
3275
3276 + netdataCheckXSS = false; // disable the modal - this does not affect XSS checks, since dashboard.js is already loaded
3277 + NETDATA.xss.enabled = true; // we should not do any remote requests, but if we do, check them
3278 + NETDATA.xss.enabled_for_data = true; // check also snapshot data - that have been excluded from the initial check, due to compression
3279 initializeDynamicDashboard();
3280 + loadSnapshotPreflightEmpty();
3281 });
3282 });
3283 };
@@ -4318,6 +4323,13 @@
4323 NETDATA.globalPanAndZoom.setMaster(NETDATA.options.targets[0], netdataSnapshotData.after_ms, netdataSnapshotData.before_ms);
4324 }
4325
4326 + if(typeof netdataCheckXSS !== 'undefined' && netdataCheckXSS === true) {
4327 + setTimeout(function() {
4328 + document.getElementById('netdataXssModalServer').innerText = netdataServer;
4329 + $('#xssModal').modal('show');
4330 + }, 1000);
4331 + }
4332 +
4333 // var netdataEnded = performance.now();
4334 // console.log('start up time: ' + (netdataEnded - netdataStarted).toString() + ' ms');
4335 }
@@ -4579,6 +4591,39 @@
4591 </div>
4592 </div>
4593
4594 + <div class="modal fade" id="xssModal" tabindex="-1" role="dialog" aria-labelledby="xssModalLabel">
4595 + <div class="modal-dialog modal-lg" role="document">
4596 + <div class="modal-content">
4597 + <div class="modal-header">
4598 + <button type="button" class="close" data-dismiss="modal" aria-label="Close"><span aria-hidden="true">&times;</span></button>
4599 + <h4 class="modal-title" id="xssModalLabel">XSS Protection</h4>
4600 + </div>
4601 + <div class="modal-body">
4602 + <p>
4603 + This dashboard is now rendering data of server:
4604 + </p>
4605 + <p style="font-size: 1.25em;">
4606 + <code id="netdataXssModalServer"></code>
4607 + </p>
4608 + <p>
4609 + To protect your privacy, the dashboard is <b>checking all data transferred</b> for cross site scripting (XSS).
4610 + This is CPU intensive, so your browser might be a bit slower.
4611 + </p>
4612 + <p>
4613 + If you <b>trust</b> the remote server, you can disable XSS protection, to speed it up.
4614 + <br/>
4615 + If you <b>don't trust</b> the remote server, you better keep it on. The dashboard will be a bit slower,
4616 + but better be safe, than sorry...
4617 + </p>
4618 + </div>
4619 + <div class="modal-footer">
4620 + <a href="#" onclick="NETDATA.xss.enabled = true; NETDATA.xss.enabled_for_data = true; return false;" type="button" class="btn btn-success" data-dismiss="modal">Keep protecting me</a>
4621 + <a href="#" onclick="NETDATA.xss.enabled = false; NETDATA.xss.enabled_for_data = false; return false;" type="button" class="btn btn-danger" data-dismiss="modal">I don't need this, the server is mine</a>
4622 + </div>
4623 + </div>
4624 + </div>
4625 + </div>
4626 +
4627 <div class="modal fade" id="printPreflightModal" tabindex="-1" role="dialog" aria-labelledby="printPreflightModalLabel">
4628 <div class="modal-dialog modal-lg" role="document">
4629 <div class="modal-content">