Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

CSP: wasm loads via data: URI fetch (blocked by connect-src 'self') and init() offers no wasm path override

オープン
#188 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
70/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
typescript, wasm
領域
security, web-dev

調査の方向性

lib/ghostty.ts から始め、init() と Ghostty.load(wasmPath?) およびその defaultPaths を比較します。公開される bundle と dist/ghostty-vt.wasm がどのように生成されるかを確認し、その後 README の CSP に関するガイダンスを確認します。init() が失敗する data: の試行なしに connect-src 'self' の下で同梱された wasm を読み込め、選択した読み込みパスについてテストまたは文書化された検証があれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Context

Same evaluation as #187 — considering ghostty-web for the SSH/Kubernetes terminals in Cloud Foundry Stratos, this time measuring startup under a Content-Security-Policy. Functionally the probe went well: rendering, canvas selection, and the fit() → onResize resize contract all worked. What did not survive is wasm loading under a strict-but-ordinary policy. Full measurements are recorded here.

What happens under connect-src 'self'

Policy used (a fairly common strict baseline, and Stratos's shipped default):

default-src 'self'; script-src 'self'; connect-src 'self'; ...

With [email protected], await init() fails in three steps:

  1. The first candidate the loader tries is the module URL — but in the published bundle the wasm is inlined as a base64 data: URI, so the module-relative URL is a data: URL. fetch() of a data: URL is subject to connect-src, and 'self' blocks it. One CSP violation is logged per load.
  2. The fallbacks ./ghostty-vt.wasm and /ghostty-vt.wasm resolve against the page, not the module — 404 unless the deployment happens to serve the wasm at the document root.
  3. init() takes no arguments, so there is no way to point the loader at the real file (which does ship in dist/ghostty-vt.wasm).

Result: Error: Failed to fetch WASM: 404 Not Found, and the terminal cannot start at all under a policy that plain xterm.js runs under.

Reading lib/ghostty.ts, the capability already exists one layer down: Ghostty.load(wasmPath?) accepts an explicit path and defaultPaths puts the module-relative URL first — the gap is only that init() does not expose it, and that bundling turns the module-relative default into a data: URI.

Suggestions

  1. Plumb the path through init() — init(wasmPath?: string) or init({ wasmUrl }), forwarding to Ghostty.load(). This alone unblocks any CSP-constrained embedder, and it looks like a one-line change given load() already takes it.
  2. Publish the bundle without inlining the wasm, so the module-relative candidate resolves to the real dist/ghostty-vt.wasm file — or at least order the same-origin candidates before the data: fallback. Beyond CSP, the inlining also carries ~560KB of base64 in the JS bundle for a 413KB binary that ships in the package anyway, and even when loading eventually succeeds by another route, the data: attempt logs a CSP violation on every page load, which is noise for anyone running violation reporting.
  3. A docs note on 'wasm-unsafe-eval' — once the fetch succeeds, WebAssembly.compile() still requires script-src to include 'wasm-unsafe-eval'. That one is inherent to running wasm under CSP rather than anything ghostty-web can fix, but a line in the README would save the next embedder the discovery cost.

For what it's worth, with the wasm served at the document root and 'wasm-unsafe-eval' added, everything downstream passed cleanly in our probe — zero style violations, correct rendering, selection and resize all good. The loading path is the only blocker.

主要言語
TypeScript
スター
2.9k
フォーク
174
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

coder/ghostty-web のほかの issue

coder/ghostty-web の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。