Skip to content

Commit a142b8e

Browse files
committed
๐Ÿ›ก๏ธ Sentinel: [security improvement]
1 parent 6969e68 commit a142b8e

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

โ€Ž.jules/sentinel.mdโ€Ž

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
**Prevention:** ์ ์šฉ ๊ฐ€๋Šฅํ•  ๋•Œ๋Š” ํ•ญ์ƒ CSP์— Trusted Types๋ฅผ ์ ์šฉํ•˜์—ฌ DOM XSS ํšŒ๊ท€๋ฅผ ์„ ์ œ์ ์œผ๋กœ ๋ฐฉ์ง€ํ•ด์•ผ ํ•จ.
2121
## 2026-07-03 - Native Trusted Types enforcement
2222
**Vulnerability:** Trusted Types ์ •์ฑ… ๋ถ€์žฌ๋กœ ์ธํ•œ DOM ๊ธฐ๋ฐ˜ XSS (Cross-Site Scripting) ์ทจ์•ฝ์  ์œ„ํ—˜.
23-
**Learning:** ์ด ์ •์  ์›น์‚ฌ์ดํŠธ๋Š” `innerHTML` ๊ฐ™์€ ์œ„ํ—˜ํ•œ Sink๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  `textContent`, `setAttribute` ๋“ฑ ์•ˆ์ „ํ•œ DOM API๋งŒ์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์œผ๋ฏ€๋กœ, ๋ณ„๋„์˜ Trusted Types ์ •์ฑ…์ด๋‚˜ ์™ธ๋ถ€ Sanitizer(์˜ˆ: DOMPurify) ์—†์ด๋„ CSP์—์„œ `require-trusted-types-for 'script'`๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ๊ธฐ๋ณธ ๊ฐ•์ œํ•  ์ˆ˜ ์žˆ์Œ์„ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.
23+
**Learning:** ์ด ์ •์  ์›น์‚ฌ์ดํŠธ๋Š” `innerHTML` ๊ฐ™์€ ์œ„ํ—˜ํ•œ Sink๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  `textContent`, `setAttribute` ๋“ฑ ์•ˆ์ „ํ•œ DOM API๋งŒ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์œผ๋ฏ€๋กœ, ๋ณ„๋„์˜ Trusted Types ์ •์ฑ…์ด๋‚˜ ์™ธ๋ถ€ Sanitizer(์˜ˆ: DOMPurify) ์—†์ด๋„ CSP์—์„œ `require-trusted-types-for 'script'`๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ๊ธฐ๋ณธ ๊ฐ•์ œํ•  ์ˆ˜ ์žˆ์Œ์„ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.
2424
**Prevention:** CSP์— `require-trusted-types-for 'script'`๋ฅผ ์ ์šฉํ•˜์—ฌ XSS๋ฅผ ๋ฐฉ์–ดํ•˜๊ณ , ์•ž์œผ๋กœ๋„ ์•ˆ์ „ํ•œ DOM API๋งŒ ์‚ฌ์šฉํ•˜๋„๋ก ํ•ฉ๋‹ˆ๋‹ค. ๋ถ€๋“์ดํ•˜๊ฒŒ `innerHTML`์„ ๋„์ž…ํ•ด์•ผ ํ•  ๊ฒฝ์šฐ์—๋Š” ๋ฐ˜๋“œ์‹œ ์ ์ ˆํ•œ Sanitizer๋ฅผ ํ•จ๊ป˜ ๊ตฌ์„ฑํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
2525
## 2026-07-01 - Add Trusted Types Policy via DOMPurify
2626
**Vulnerability:** Application lacked Trusted Types enforcement, which left it potentially vulnerable to DOM-based XSS if DOM sinks (like `innerHTML`) were manipulated.

0 commit comments

Comments
ย (0)