ask for xss approval before loading remote content
Costa Tsaousis (ktsaou) committed
Jan 30, 2018 at 00:31 UTC
7734abbb94a3a65d44ca927d7ed728fef96d74ac
2 files changed
+78
-38
web/dashboard.js
+3
-3
@@ -168,20 +168,20 @@ var NETDATA = window.NETDATA || {};
168
169
checkOptional: function(name, obj, ignore_regex) {
170
if(this.enabled === true) {
171
- console.log('XSS: checking optional "' + name + '"...');
171
+ //console.log('XSS: checking optional "' + name + '"...');
172
return this.object(name, obj, ignore_regex);
173
}
174
return obj;
175
},
176
177
checkAlways: function(name, obj, ignore_regex) {
178
- console.log('XSS: checking always "' + name + '"...');
178
+ //console.log('XSS: checking always "' + name + '"...');
179
return this.object(name, obj, ignore_regex);
180
},
181
182
checkData: function(name, obj, ignore_regex) {
183
if(this.enabled_for_data === true) {
184
- console.log('XSS: checking data "' + name + '"...');
184
+ //console.log('XSS: checking data "' + name + '"...');
185
return this.object(name, obj, ignore_regex);
186
}
187
return obj;
web/index.html
+75
-35
@@ -2812,32 +2812,78 @@
2812
}
2813
}
2814
2815
+ // an object to keep initilization configuration
2816
+ // needed due to the async nature of the XSS modal
2817
+ var initializeConfig = {
2818
+ url: null,
2819
+ custom_info: true,
2820
+ };
2821
+
2822
+ function loadCustomDashboardInfo(url, callback) {
2823
+ loadJs(url, function () {
2824
+ $.extend(true, netdataDashboard, customDashboard);
2825
+ callback();
2826
+ });
2827
+ }
2828
+
2829
+ function initializeChartsAndCustomInfo() {
2830
+ NETDATA.alarms.callback = alarmsCallback;
2831
+
2832
+ // download all the charts the server knows
2833
+ NETDATA.chartRegistry.downloadAll(initializeConfig.url, function(data) {
2834
+ if(data !== null) {
2835
+ if (initializeConfig.custom_info === true && typeof data.custom_info !== 'undefined' && data.custom_info !== "" && netdataSnapshotData === null) {
2836
+ //console.log('loading custom dashboard decorations from server ' + initializeConfig.url);
2837
+ loadCustomDashboardInfo(NETDATA.serverDefault + data.custom_info, function () {
2838
+ initializeDynamicDashboardWithData(data);
2839
+ });
2840
+ }
2841
+ else {
2842
+ //console.log('not loading custom dashboard decorations from server ' + initializeConfig.url);
2843
+ initializeDynamicDashboardWithData(data);
2844
+ }
2845
+ }
2846
+ });
2847
+ }
2848
+
2849
+ function xssModalDisableXss() {
2850
+ //console.log('disabling xss checks');
2851
+ NETDATA.xss.enabled = false;
2852
+ NETDATA.xss.enabled_for_data = false;
2853
+ initializeConfig.custom_info = true;
2854
+ initializeChartsAndCustomInfo();
2855
+ return false;
2856
+ }
2857
+
2858
+ function xssModalKeepXss() {
2859
+ //console.log('keeping xss checks');
2860
+ NETDATA.xss.enabled = true;
2861
+ NETDATA.xss.enabled_for_data = true;
2862
+ initializeConfig.custom_info = false;
2863
+ initializeChartsAndCustomInfo();
2864
+ return false;
2865
+ }
2866
+
2867
function initializeDynamicDashboard(netdata_url) {
2868
if(typeof netdata_url === 'undefined' || netdata_url === null)
2869
netdata_url = NETDATA.serverDefault;
2870
2871
+ initializeConfig.url = netdata_url;
2872
+
2873
// initialize clickable alarms
2874
NETDATA.alarms.chart_div_offset = -50;
2875
NETDATA.alarms.chart_div_id_prefix = 'chart_';
2876
NETDATA.alarms.chart_div_animation_duration = 0;
2877
2878
NETDATA.pause(function() {
2825
- NETDATA.alarms.callback = alarmsCallback;
2826
-
2827
- // download all the charts the server knows
2828
- NETDATA.chartRegistry.downloadAll(netdata_url, function(data) {
2829
- if(data !== null) {
2830
- if(typeof data.custom_info !== 'undefined' && data.custom_info !== "" && netdataSnapshotData === null) {
2831
- loadJs(NETDATA.serverDefault + data.custom_info, function () {
2832
- $.extend(true, netdataDashboard, customDashboard);
2833
- initializeDynamicDashboardWithData(data);
2834
- });
2835
- }
2836
- else {
2837
- initializeDynamicDashboardWithData(data);
2838
- }
2839
- }
2840
- });
2879
+ if(typeof netdataCheckXSS !== 'undefined' && netdataCheckXSS === true) {
2880
+ //$("#loadOverlay").css("display","none");
2881
+ document.getElementById('netdataXssModalServer').innerText = initializeConfig.url;
2882
+ $('#xssModal').modal('show');
2883
+ }
2884
+ else {
2885
+ initializeChartsAndCustomInfo();
2886
+ }
2887
});
2888
}
2889
@@ -3276,8 +3322,8 @@
3322
netdataCheckXSS = false; // disable the modal - this does not affect XSS checks, since dashboard.js is already loaded
3323
NETDATA.xss.enabled = true; // we should not do any remote requests, but if we do, check them
3324
NETDATA.xss.enabled_for_data = true; // check also snapshot data - that have been excluded from the initial check, due to compression
3279
- initializeDynamicDashboard();
3325
loadSnapshotPreflightEmpty();
3326
+ initializeDynamicDashboard();
3327
});
3328
});
3329
};
@@ -4323,13 +4369,6 @@
4369
NETDATA.globalPanAndZoom.setMaster(NETDATA.options.targets[0], netdataSnapshotData.after_ms, netdataSnapshotData.before_ms);
4370
}
4371
4326
- if(typeof netdataCheckXSS !== 'undefined' && netdataCheckXSS === true) {
4327
- setTimeout(function() {
4328
- document.getElementById('netdataXssModalServer').innerText = netdataServer;
4329
- $('#xssModal').modal('show');
4330
- }, 1000);
4331
- }
4332
-
4372
// var netdataEnded = performance.now();
4373
// console.log('start up time: ' + (netdataEnded - netdataStarted).toString() + ' ms');
4374
}
@@ -4591,34 +4630,35 @@
4630
</div>
4631
</div>
4632
4594
- <div class="modal fade" id="xssModal" tabindex="-1" role="dialog" aria-labelledby="xssModalLabel">
4633
+ <div class="modal fade" id="xssModal" tabindex="-1" role="dialog" aria-labelledby="xssModalLabel" data-keyboard="false" data-backdrop="static" style="z-index: 3000">
4634
<div class="modal-dialog modal-lg" role="document">
4635
<div class="modal-content">
4636
<div class="modal-header">
4598
- <button type="button" class="close" data-dismiss="modal" aria-label="Close"><span aria-hidden="true">×</span></button>
4637
<h4 class="modal-title" id="xssModalLabel">XSS Protection</h4>
4638
</div>
4639
<div class="modal-body">
4640
<p>
4603
- This dashboard is now rendering data of server:
4641
+ This dashboard is about to render data from server:
4642
</p>
4643
<p style="font-size: 1.25em;">
4644
<code id="netdataXssModalServer"></code>
4645
</p>
4646
<p>
4609
- To protect your privacy, the dashboard is <b>checking all data transferred</b> for cross site scripting (XSS).
4610
- This is CPU intensive, so your browser might be a bit slower.
4647
+ To protect your privacy, the dashboard will <b>check all data transferred</b> for cross site scripting (XSS).
4648
+ <br/>This is CPU intensive, so your browser might be a bit slower.
4649
</p>
4650
<p>
4613
- If you <b>trust</b> the remote server, you can disable XSS protection, to speed it up.
4614
- <br/>
4615
- If you <b>don't trust</b> the remote server, you better keep it on. The dashboard will be a bit slower,
4616
- but better be safe, than sorry...
4651
+ If you <b>trust</b> the remote server, you can disable XSS protection.<br/>
4652
+ In this case, any remote dashboard decoration code (javascript) will also run.
4653
+ </p>
4654
+ <p>
4655
+ If you <b>don't trust</b> the remote server, you should keep the protection on.<br/>
4656
+ The dashboard will run slower and remote dashboard decoration code will not run, but better be safe than sorry...
4657
</p>
4658
</div>
4659
<div class="modal-footer">
4620
- <a href="#" onclick="NETDATA.xss.enabled = true; NETDATA.xss.enabled_for_data = true; return false;" type="button" class="btn btn-success" data-dismiss="modal">Keep protecting me</a>
4621
- <a href="#" onclick="NETDATA.xss.enabled = false; NETDATA.xss.enabled_for_data = false; return false;" type="button" class="btn btn-danger" data-dismiss="modal">I don't need this, the server is mine</a>
4660
+ <a href="#" onclick="return xssModalKeepXss();" type="button" class="btn btn-success" data-dismiss="modal">Keep protecting me</a>
4661
+ <a href="#" onclick="return xssModalDisableXss();" type="button" class="btn btn-danger" data-dismiss="modal">I don't need this, the server is mine</a>
4662
</div>
4663
</div>
4664
</div>