Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Unable to use extensions that depend on unsafe-eval policy, in code-editor

Đang mở
#301 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
52/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
javascript
Lĩnh vực
frontend, security

Hướng nghiên cứu

Bắt đầu bằng cách lần theo cách Code Editor tải các extension CommonJS trong web/worker host và nơi policy CSP được cấu hình. Tái hiện việc kích hoạt extension vscodevim.vim, sau đó xác minh rằng extension này hoạt động theo policy dự kiến mà không gặp EvalError được báo cáo.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Description:
The change in the security policy from unsafe-eval to wasm-unsafe-eval stops JavaScript from turning strings into runnable code.

  • Vim is a CommonJS format extension.
  • When Code Editor loads a CommonJS extension in the web/worker host, it wraps the code string in a function and executes it.
  • In the Code Editor space, the new CSP policy blocks that step, so it fails.

2026-09-10 16:47:24.991 [error] Activating extension vscodevim.vim failed due to an error: 2026-09-10 16:47:24.991 [error] EvalError: Evaluating a string as JavaScript violates the following Content Security Policy directive because 'unsafe-eval' is not an allowed source of script: script-src 'self' 'wasm-unsafe-eval' 'sha256-8VDNIuBNbWfgSAsMFpnaas1UmjLKHwTaKfM2t/FPUfc=' https: http://localhost:* blob:".

https://www.w3.org/TR/CSP3/#directive-script-src
Per the CSP spec, new Function() is gated only on 'unsafe-eval'; 'wasm-unsafe-eval' "only permits WebAssembly and does not affect JavaScript." So replacing 'unsafe-eval' with 'wasm-unsafe-eval' removes the exact permission the extension loader needs, and the browser throws EvalError.

Ticket ID: D523182748

Ngôn ngữ chính
Shell
Star
26
Fork
24
Merge trung bình
10 phút
Pull request đã merge (30 ngày)
3

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của aws/code-editor

Tất cả issue của aws/code-editor

Issue tương tự

Thêm issue về Shell/Bash

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.