* Studio: stop leaking the auth token through HTML canvas preview frames The artifact preview frame placed the Studio bearer token in the iframe URL (?token=) whenever canvas network access was enabled. Untrusted canvas HTML runs in that frame and can read its own window.location.href, and the network-mode CSP allows outbound http/https, so the token could be exfiltrated and replayed against authenticated Studio APIs. The auto-render HTML cards widened the reach: ordinary or prompt-injected assistant html fences become a Preview card that opens this same frame, and the render_html tool path auto-opens it without a click. Root cause: never put the token in the frame URL. The preview shell is a static document that only renders HTML posted to it by its embedder, and frame-ancestors plus the no-same-origin sandbox already constrain it, so the endpoint no longer accepts or validates the token and selects the network CSP from allow_network alone. No credential ever reaches the frame. Defense in depth: only tool-rendered canvases may opt into network mode; fences auto-extracted from assistant text never do. * Studio: stop strict canvas frames from self-upgrading to network mode Network mode is selected from the allow_network query param alone, so untrusted canvas code in a strict frame could navigate its own iframe to ?allow_network=1; the frame's onLoad handler then reposted the same untrusted HTML into the now network-enabled frame, giving a no-network or fenced canvas unauthorized network egress. Only inject the artifact for loads we initiated (mount or a src change), tracked by a pending flag set when src changes. A self-navigation also fires onLoad but is no longer fed, so the upgraded frame stays the inert shell. The strict CSP default-src 'none' already blocks the child-iframe variant. * Studio: trim comments in the canvas artifact security fix Condense the added explanatory comments and the artifact-preview-frame docstring to one line each while keeping the security rationale. No code change (verified comment-only). |
||
|---|---|---|
| .. | ||
| assets | ||
| auth | ||
| core | ||
| hub | ||
| loggers | ||
| models | ||
| plugins | ||
| requirements | ||
| routes | ||
| state | ||
| storage | ||
| tests | ||
| utils | ||
| __init__.py | ||
| _platform_compat.py | ||
| cloudflare_tunnel.py | ||
| colab.py | ||
| main.py | ||
| run.py | ||
| startup_banner.py | ||