Shipped nginx/Netlify configs set no CSP, frame-ancestors or referrer policy #44
Closed
opened 2026-09-12 01:51:10 -04:00 by jared
·
1 comment
No Branch/Tag Specified
lotus
update-packages
sw-fix
read-me-update
image-path-changes
dm-calls
fix-2469
renovate/element-hq-element-call-embedded-0.x
renovate/npm-i18next-http-backend-vulnerability
renovate/npm-vite-vulnerability
dev
docs-update
more-theme
fix-257
imporve-thread-reply
revert-2402-improve-menu-congestion
mxidColor-toggle
update-sw-main-msg
v4.11.1
v4.10.5
v4.10.4
v4.10.3
v4.10.2
v4.10.1
v4.10.0
v4.9.1
v4.9.0
v4.8.1
v4.8.0
v4.7.1
v4.7.0
v4.6.0
v4.5.1
v4.5.0
v4.4.0
v4.3.2
v4.3.0
v4.2.3
v4.2.2
v4.2.1
v4.2.0
v4.1.0
v4.0.3
v4.0.0
v3.2.0
v3.1.0
v3.0.0
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2.0
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.8.2
v1.8.1
v1.8.0
v1.7.0
v1.6.1
v1.6.0
v1.5.1
v1.5.0
v1.4.0
v1.3.2
v1.3.1
v1.3.0
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Labels
Clear labels
a11y
area: appearance
area: auth-session
area: build-ci
area: calls
area: desktop
area: media
area: messaging
area: mobile
area: moderation
area: navigation
area: notifications
area: settings
area: threads
bug
dependencies
docs
duplicate
enhancement
help wanted
invalid
needs-human-review
performance
planning
priority: critical
priority: high
priority: low
priority: medium
qa
question
research
security
tech-debt
ux
wontfix
Accessibility: keyboard, screen reader, contrast, motion
Client area: appearance
Client area: auth-session
Client area: build-ci
Client area: calls
Client area: desktop
Client area: media
Client area: messaging
Client area: mobile
Client area: moderation
Client area: navigation
Client area: notifications
Client area: settings
Client area: threads
Something is not working
Third-party package versions and advisories
README / LOTUS_* docs wrong or missing
This issue or pull request already exists
New feature
Need some help
Something is wrong
Re-render storms, leaks, heavy work on hot paths
Data loss, security hole, or crash on a main path
Broken feature or serious usability problem
Minor issue or polish
Wrong behaviour in an edge case or notable degradation
Manual QA: shipped, needs a human in a real environment
More information is needed
XSS, unsafe URLs, data leaks, auth/session
Code health, dead code, fragile patterns
Usability or visual inconsistency
This won't be fixed
Milestone
No items
No Milestone
Audit 2026-09 · Medium & Low
Projects
Clear projects
No projects
Notifications
Due Date
Dependencies
No dependencies set.
Reference: LotusGuild/cinny#44
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: medium · Type: security · Confidence: high
Location:
docker-nginx.conf:1-19,netlify.toml:1-40,index.html(no<meta http-equiv="Content-Security-Policy">)Problem
the embed code treats CSP as its primary control —
EMBED_SANDBOXis documented as"Defense-in-depth on top of the CSP frame-src allowlist"
(
src/app/components/url-preview/UrlPreviewCard.tsx:621-624) — andLOTUS_TODO.mdreasons about aprod
frame-src 'self' https:. But no CSP exists anywhere in the repo: the Docker nginx server blockemits no headers at all,
netlify.tomlonly has redirects, andindex.htmlhas no CSP meta tag. Anydeployment built from this repo (the Dockerfile is the documented path) therefore runs with no
frame-srcrestriction, noframe-ancestors(the client is framable → clickjacking against themessage composer / verification flows), no
Referrer-Policy, and noX-Content-Type-Options. Theproduction CSP evidently lives in infrastructure outside this repo, which means it is silently absent
for every other deployment and is not covered by any check here.
How to trigger
docker build . && docker run …, thencurl -I http://localhost/— no security headers; embed the app in a third-party<iframe>— it renders.Suggested fix
add
add_headerdirectives todocker-nginx.conf(CSP with an explicitframe-srcallowlist matching
videoEmbed.ts,frame-ancestors 'none',Referrer-Policy: no-referrer,X-Content-Type-Options: nosniff) and the equivalent[[headers]]block innetlify.toml, so thecontrol the client code depends on ships with the client.
Filed from the September 2026 client audit (branch
lotus@4bea4895).Production already sent a full CSP (frame-ancestors 'none', HSTS, nosniff, referrer policy), so the original finding only applied to the shipped Docker/Netlify configs — fixed in
039b74c2(#95). While verifying, found the real problem: the host's nginx config was older than the tracked one because LXC 106's webhook config had lost the matrix-deploy hook on 2026-05-21, so nothing from the matrix repo had deployed there since (widget-friendlyframe-src 'self' https:from July never landed). Fixed today: tracked nginx.conf installed and reloaded (live headers verified), deploy helpers reinstalled, hooks.json restored as the union of all three hooks (matrix@d3ee2e2), webhook restarted.