Both mdNode implementations (agent UI app.js, dashboard common.js) assigned marked.parse() output straight to innerHTML with no sanitizer. marked v5+ dropped its built-in sanitize option, and there was no DOMPurify anywhere in frontend/, so markdown containing raw HTML/script tags rendered live in the browser. Both sinks receive untrusted input in practice: the agent UI's mdNode renders recv tool_result bodies, assistant prose, and send/ask/answer payloads sourced from peer agents and matrix-relayed messages (the documented prompt-injection adversary); the dashboard's mdNode renders agent-authored .md files served verbatim by GET /api/state-file (the endpoint validates path, not content). Since the per-agent UI and dashboard are same-origin behind the gateway with operator-authority endpoints (approve/spawn/rebuild/destroy/answer-question), injected script would run with the operator's session. Fix: DOMPurify.sanitize() the marked.parse() output at both sinks before assigning to innerHTML. Added dompurify as a dependency to both the agent and dashboard npm workspaces, recomputed npmDepsHash in nix/frontend.nix for the updated lockfile. Also corrected docs/web-ui/shape.md, which claimed the markdown-rendering path was XSS-safe by construction the same way the text-node-based linkify path is — it isn't; it's safe because it's sanitized. CSP hardening for the dashboard (no unsafe-inline) is a separate, larger backend change (response headers in hive-c0re) and is left as a fast-follow rather than folded into this fix.
67 lines
2.6 KiB
Nix
67 lines
2.6 KiB
Nix
{
|
|
buildNpmPackage,
|
|
lib,
|
|
branding-svg,
|
|
}:
|
|
|
|
# Hermetic build of the npm-managed frontend workspaces (see
|
|
# `frontend/README.md`). Consumes `frontend/package-lock.json` as the
|
|
# source of truth for dependency versions; `npmDepsHash` pins the
|
|
# vendor-tarball hash so a stale lockfile fails the build instead of
|
|
# silently fetching different upstream tarballs.
|
|
#
|
|
# Output layout (`$out`) — two subdirectories, one per surface, that
|
|
# the Rust binaries serve via `tower_http::ServeDir`:
|
|
#
|
|
# $out/dashboard/ the hive-c0re dashboard assets (full layout in
|
|
# frontend/packages/dashboard/build.mjs):
|
|
# index.html (H0M3 hub, served at /) dashboard.html (operator SPA,
|
|
# served at /dashboard.html) flow.html logs.html settings.html
|
|
# stats.html favicon.svg
|
|
# static/{home,tabs,flow,logs,settings,stats,stream-worker}.js{,.map}
|
|
# static/{colors,theme,common,home,dashboard,flow,logs,settings,stats}.css
|
|
# $out/agent/ the per-agent default UI (layered with
|
|
# hyperhive.frontend.extraFiles at activation time)
|
|
# index.html stats.html screen.html
|
|
# static/{app,stats}.js{,.map}
|
|
# static/{colors,theme,agent}.css
|
|
#
|
|
# The dashboard favicon lives outside the npm tree (`branding/hyperhive
|
|
# .svg` at the repo root) — we copy it in during the install phase so
|
|
# the served prefix has everything in one place.
|
|
|
|
buildNpmPackage {
|
|
pname = "hyperhive-frontend";
|
|
version = "0.0.0";
|
|
src = ../frontend;
|
|
|
|
# Computed from `frontend/package-lock.json` via
|
|
# prefetch-npm-deps frontend/package-lock.json
|
|
# Update whenever the lockfile changes. Recompute locally with the
|
|
# same command (`pkgs.prefetch-npm-deps`), or let the build fail
|
|
# and copy the actual hash from the error message.
|
|
npmDepsHash = "sha256-/aklU+l5HqSs4l68gf9J3mgyKM30reBgTkaEjtx2MNY=";
|
|
|
|
# `npm run build` recurses into all workspaces (`--workspaces
|
|
# --if-present`). The workspaces' build scripts each run their own
|
|
# `build.mjs` (esbuild).
|
|
npmBuildScript = "build";
|
|
|
|
# buildNpmPackage's default install phase copies the working dir into
|
|
# $out, which is overkill — we only want the dist trees. Hand-roll
|
|
# the install to keep $out tight.
|
|
dontNpmInstall = true;
|
|
installPhase = ''
|
|
runHook preInstall
|
|
mkdir -p $out/dashboard $out/agent
|
|
cp -r packages/dashboard/dist/. $out/dashboard/
|
|
cp -r packages/agent/dist/. $out/agent/
|
|
cp ${branding-svg} $out/dashboard/favicon.svg
|
|
runHook postInstall
|
|
'';
|
|
|
|
meta = {
|
|
description = "Bundled browser-facing assets for the hyperhive dashboard and per-agent UI";
|
|
homepage = "https://forge.darkest.space/hyperhive/hyperhive";
|
|
};
|
|
}
|