Support Trusted Types (require-trusted-types-for 'script')
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Cần làm rõ
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- react, typescript
Hướng nghiên cứu
Start with the shared policy helper in #24738 and trace its use from showReportDialog. Then inspect the Replay compression worker, Feedback form, lazyLoadIntegration, loader script, and error-page-embed.js paths named in the report. Done means the affected sinks work under require-trusted-types-for 'script', with the policy and CSP requirements documented.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Problem Statement
Apps that enforce Trusted Types (Content-Security-Policy: require-trusted-types-for 'script') can't use several SDK features without a pass-through default policy, which disables Trusted Types for the whole page.
Repro: https://github.com/oioki/trusted-types-sentry-js-sdk. It's a minimal Vite + React app with @sentry/react 11.0.0 and no Trusted Types policies of its own, so every violation comes from the SDK.
| Sink | Where | Enforced result | Workaround |
|---|---|---|---|
new Worker(url) |
Replay compression worker | Caught; replay continues | useCompression: false (larger payloads) |
innerHTML |
Feedback form (dangerouslySetInnerHTML: logo, success icon, screenshot styles) |
Form doesn't render | showBranding: false covers the logo only |
script.src |
showReportDialog() |
Throws, no dialog | None |
innerHTML |
error-page-embed.js (served by Sentry) |
Blocked once the dialog loads | None |
script.src |
lazyLoadIntegration() |
Throws | None |
script.src |
Loader Script | Throws | None |
The workaround in #15913 (workerUrl) doesn't help: new Worker(url) requires a TrustedScriptURL for any string URL, not just blob: URLs, so a self-hosted worker still violates.
Teams with a strict CSP (enterprise, fintech, public sector, Angular and Lit users) currently have to choose between Sentry's Replay, Feedback and User Feedback dialog and enforcing Trusted Types. Teams in report-only rollout also get SDK noise in their violation reports, with no policy name they can allow.
Solution Brainstorm
- The SDK creates one named policy, e.g.
sentry-sdk, that validates rather than passes values through. It would allow only script URLs the SDK builds itself (DSN host plus the known paths, the CDN) and only static HTML. Apps allow it withtrusted-types sentry-sdk. - Remove the
innerHTMLuses in feedback by building the SVG and styles with DOM APIs. - Document the CSP needed (
trusted-types sentry-sdk, and'allow-duplicates'when more than one SDK copy is on the page).
Additional Context
#24738 is a first step: a shared sentry-sdk policy helper, used by showReportDialog.
Priority
React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding +1 or me too, to help us triage it.
- Ngôn ngữ chính
- TypeScript
- Star
- 8.7k
- Fork
- 1.9k
- Merge trung bình
- 1 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 523
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của getsentry/sentry-javascript
-
Next.js: basePath is concatenated onto absolute router.push hrefs, corrupting navigation transaction namesCó thể đã có người làm @Lms24 đã nhận 3 ngày trước. Đang mởBrowser Bug Next.js Traces
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
getsentry/sentry-javascript#24672 · 2 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
-
javascript
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
getsentry/sentry-javascript#24200 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
javascript Task
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
getsentry/sentry-javascript#24134 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Cloudflare Workers javascript Tests
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
getsentry/sentry-javascript#24051 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Bug Bun javascript
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 92/100
getsentry/sentry-javascript#24045 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của getsentry/sentry-javascript
Issue tương tự
-
bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
StabilityNexus/Fate-EVM-Frontend#153 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
code-yeongyu/oh-my-openagent#9039 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Tencent/teamai-cli#862 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug good first issue hacktoberfest redis
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
libredb/libredb-studio#1164 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
flake
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
coder/xum#4920 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày