fix: re-check Dune allowlist before mounting sheet iframes - #412
Open
resistanceisliberty wants to merge 1 commit into
Open
fix: re-check Dune allowlist before mounting sheet iframes#412resistanceisliberty wants to merge 1 commit into
resistanceisliberty wants to merge 1 commit into
Conversation
Collab can sync arbitrary iframe src values that skip the Dune UI sanitizer. Validate on insert, remote setSheetIframes, and render so viewers do not load non-allowlisted origins when opening a sheet.
|
Someone is attempting to deploy a commit to the fileverse Team on Vercel. A member of the Team first needs to authorize it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
It looks like the Dune URL checks only apply when something is added through the normal UI. The floating iframe layer just mounts
srcfrom sheet state, and thatiframeslist is shared over collab.So if someone with write access puts a non-Dune URL into that data, viewers can could be exposed to a malicious embed - not by using the embed dialog or clicking a particular cell.
This change runs the same allowlist again before an iframe is shown, when one is inserted, and when remote collab applies iframe updates. I also tightened the sanitizer so plain
https://dune.com/embeds/…values (what the app actually stores) still count as valid; without that, real Dune charts would break under a render-time check.To see if this works
node src/sheet-engine/core/modules/iframe.sanitize.test.mjssrcshows the blocked state and does not load in the network panel