提交 a25c6e66 编写于 作者: M Matt Bierner

Add CSP

上级 f735e062
...@@ -124,6 +124,8 @@ export class Preview extends Disposable { ...@@ -124,6 +124,8 @@ export class Preview extends Disposable {
src: this.getResourcePath(this.webviewEditor, this.resource, version), src: this.getResourcePath(this.webviewEditor, this.resource, version),
}; };
const nonce = Date.now().toString();
return /* html */`<!DOCTYPE html> return /* html */`<!DOCTYPE html>
<html lang="en"> <html lang="en">
<head> <head>
...@@ -131,14 +133,16 @@ export class Preview extends Disposable { ...@@ -131,14 +133,16 @@ export class Preview extends Disposable {
<meta name="viewport" content="width=device-width, initial-scale=1.0"> <meta name="viewport" content="width=device-width, initial-scale=1.0">
<meta http-equiv="X-UA-Compatible" content="ie=edge"> <meta http-equiv="X-UA-Compatible" content="ie=edge">
<title>Image Preview</title> <title>Image Preview</title>
<link rel="stylesheet" class="code-user-style" href="${escapeAttribute(this.extensionResource('/media/main.css'))}" type="text/css" media="screen">
<link rel="stylesheet" href="${escapeAttribute(this.extensionResource('/media/main.css'))}" type="text/css" media="screen" nonce="${nonce}">
<meta http-equiv="Content-Security-Policy" content="default-src 'none'; img-src 'self' ${this.webviewEditor.webview.cspSource}; script-src 'nonce-${nonce}'; style-src 'self' 'nonce-${nonce}';">
<meta id="image-preview-settings" data-settings="${escapeAttribute(JSON.stringify(settings))}"> <meta id="image-preview-settings" data-settings="${escapeAttribute(JSON.stringify(settings))}">
</head> </head>
<body class="container image scale-to-fit loading"> <body class="container image scale-to-fit loading">
<div class="loading-indicator"></div> <div class="loading-indicator"></div>
<div class="image-load-error-message">${localize('preview.imageLoadError', "An error occurred while loading the image")}</div> <div class="image-load-error-message">${localize('preview.imageLoadError', "An error occurred while loading the image")}</div>
<script src="${escapeAttribute(this.extensionResource('/media/main.js'))}"></script> <script src="${escapeAttribute(this.extensionResource('/media/main.js'))}" nonce="${nonce}"></script>
</body> </body>
</html>`; </html>`;
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册