security(frontend): add restrictive CSP and dependency audit gate - #271
Open
woahwhattheheck wants to merge 1 commit into
Open
woahwhattheheck wants to merge 1 commit into
woahwhattheheck wants to merge 1 commit into
Conversation
Closes YieldVault-Org#263. Ship a production Content-Security-Policy with related hardening headers from a single policy module, emit Netlify/Vercel hosting configs, apply the same headers on vite preview, and fail CI on critical npm audit findings or disallowed licenses. Document justified exceptions for React inline styles, html2canvas blob URLs, and Stellar Horizon/Soroban RPC origins used by Freighter-style wallet flows.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #263.
Adds a production-quality Content-Security-Policy, related hardening headers, and a dependency vulnerability/license CI gate so the wallet-facing UI constrains runtime script sources and fails closed on critical supply-chain findings.
Design
security/policy.mjs(CSP directives, justified exceptions, audit/license policy).npm run security:emit-headers→public/_headers(Netlify/Cloudflare Pages) andvercel.json(Vercel).vite previewapplies the same headers (dev HMR intentionally excluded so Vite keeps working).connect-srcallowlists Horizon + Soroban RPC origins fromsrc/lib/networks.js(plus Futurenet for contributors).CSP exceptions (justified)
style-src 'unsafe-inline'ChartContaineraspect-ratio); script-src stays strictimg-src data: blob:html2canvaschart export object URLsconnect-srcStellar Horizon/Sorobanworker-src blob:Full write-up:
docs/CSP.md.Dependency CI policy
npm auditfindings.UNKNOWNlicenses.Acceptance criteria
_headers,vercel.json, preview smoke)npm run audit:deps)WALLET_CONNECT_ORIGINSaligned toNETWORKS)Test evidence
test/security/csp.test.js— directives, nounsafe-inline/unsafe-evalinscript-src, NETWORKS origin coverage, documented exceptionstest/security/headers-integration.test.js—_headers/vercel.jsonsync + CI wire-up regressiontest/security/deps-policy.test.js— fail-on-critical policy + license allow/denynpm run smoke:headers— preview serves CSP; no inline script bodies / secret-shaped HTMLCommands:
npm test— 230 passednpm run audit:deps— OK (0 critical; high/moderate warned)npm run build— clean (tsc -b+ vite)npm run smoke:headers— OKCompatibility / rollout
public/_headersorvercel.json.Content-Security-Policymatchessecurity/policy.mjs.WALLET_CONNECT_ORIGINS+CSP_EXCEPTIONS, re-emit headers, extend tests.npm run dev) does not apply production CSP; usenpm run preview/smoke:headersfor parity.Out of scope