Skip to content

Add strict nonce CSP for the modern Svelte frontend - #2363

Draft
niemyjski wants to merge 20 commits into
mainfrom
feature/strict-dynamic-csp
Draft

niemyjski wants to merge 20 commits into
mainfrom
feature/strict-dynamic-csp

Conversation

@niemyjski

@niemyjski niemyjski commented Jul 10, 2026 •

Copy link
Copy Markdown
Member

Add strict CSP for the modern Svelte frontend, keeping core Messenger, Stripe/Link payments, telemetry, avatars and configured-origin realtime.

Authorize only scripts from the published entry pages, SvelteKit's generated scripts and Scalar's native nonce support. Preserve fresh 32-byte nonces; prevent cached/partial HTML reuse and reject unexpected partial responses. Remove unused vendor permissions. No added docs, Angular or workflow changes.

Validation: 71 focused CSP tests, frontend typecheck/lint/build and C# formatting passed. Local Chromium confirmed Vite and the built app boot, Scalar mounts, and injected scripts are blocked. Exact-head CI passed, including all four API shards, all six browser shards, client checks and Docker build.

Sources: OWASP nonce guidance, Stripe CSP, Intercom CSP, Scalar.

@niemyjski

Copy link
Copy Markdown
Member Author

Current-feedback closeout (2026-07-26):

  • Re-fetched the live head (0bddf5a) and current main (dc940dd); the PR is clean, mergeable, and zero commits behind.
  • Audited every feedback surface: 0 GraphQL review threads, 0 inline comments, 0 submitted reviews, and 0 human issue comments. The coverage-bot comment is current informational output and needs no code action.
  • Re-reviewed the complete effective diff under the thermo-nuclear maintainability bar. No additional change is justified: CSP ownership remains isolated from host wiring, Program.cs shrinks, the three runtime policies are guarded by one parity contract, no source file crosses 1,000 lines, and dev-only LiveReload transformation complexity stays confined to its middleware.
  • Local proof: SpaIndexHtmlMiddlewareTests 17/17; Svelte CSP tests 12/12; Angular CSP/renderer tests 7/7; Exceptionless.Web build succeeded with 0 warnings and 0 errors; Svelte and Angular production builds succeeded.
  • Live CI is fully green, including API, client, E2E, Docker, version, and CLA.

No follow-up commit was necessary, and draft/admin state was left unchanged.

@niemyjski niemyjski self-assigned this Jul 30, 2026
@niemyjski
niemyjski force-pushed the feature/strict-dynamic-csp branch from 0bddf5a to 7ee01eb Compare July 30, 2026 18:18
@niemyjski niemyjski changed the title Secure SPA script loading with strict CSP Add per-response CSP nonces Jul 30, 2026
@niemyjski
niemyjski force-pushed the feature/strict-dynamic-csp branch 2 times, most recently from b7eab28 to 3cb0aa3 Compare July 30, 2026 19:39
@niemyjski

Copy link
Copy Markdown
Member Author

Fixed the failing CSP fallback integration coverage in 9f10cf351 by making the integration host exercise the production response-level nonce middleware and SPA fallback delegate.

Verification after push:

  • Local test project build: 0 warnings, 0 errors
  • SpaIndexHtmlMiddlewareTests: 17/17 passed
  • CspNonceTests: 3/3 passed
  • GitHub CI: client, full API coverage suite, E2E, version, and Docker build all passed

Re-audited the review surfaces: there are no submitted reviews or review threads to resolve.

@niemyjski
niemyjski force-pushed the feature/strict-dynamic-csp branch from 8e10da9 to f8d1597 Compare September 16, 2026 00:32
@niemyjski
niemyjski force-pushed the feature/strict-dynamic-csp branch from 73784dd to 4aa1ed3 Compare September 30, 2026 03:48
@niemyjski niemyjski changed the title Add per-response CSP nonces Add strict nonce CSP for the modern Svelte frontend Sep 30, 2026
@niemyjski
niemyjski force-pushed the feature/strict-dynamic-csp branch from 50dec23 to 195d2ad Compare October 2, 2026 03:37
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Code Coverage

Package Line Rate Branch Rate Complexity Health
Exceptionless.AppHost 22% 23% 141 ❌
Exceptionless.Core 77% 68% 10820 ✔
Exceptionless.Insulation 51% 43% 370 ➖
Exceptionless.Web 86% 70% 9201 ✔
Summary 80% (27881 / 34972) 69% (13772 / 20100) 20532 ✔

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant