{"id":1179,"date":"2024-12-13T10:37:34","date_gmt":"2024-12-13T02:37:34","guid":{"rendered":"http:\/\/www.max-shu.com\/blog\/?p=1179"},"modified":"2024-12-13T10:37:35","modified_gmt":"2024-12-13T02:37:35","slug":"web%e7%9a%84%e5%86%85%e5%ae%b9%e5%ae%89%e5%85%a8%e7%ad%96%e7%95%a5cspcontent-security-policy","status":"publish","type":"post","link":"http:\/\/www.max-shu.com\/blog\/?p=1179","title":{"rendered":"WEB\u7684\u5185\u5bb9\u5b89\u5168\u7b56\u7565CSP(Content-Security-Policy)"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><strong>1.CSP \u7b80\u4ecb<\/strong><\/h2>\n\n\n\n<p>\u00a0\u00a0 \u00a0\u5185\u5bb9\u5b89\u5168\u7b56\u7565\uff08Content Security Policy\uff0c\u7b80\u79f0CSP\uff09\u662f\u4e00\u79cd\u4ee5\u53ef\u4fe1\u767d\u540d\u5355\u4f5c\u673a\u5236\uff0c\u6765\u9650\u5236\u7f51\u7ad9\u662f\u5426\u53ef\u4ee5\u5305\u542b\u67d0\u4e9b\u6765\u6e90\u5185\u5bb9\uff0c\u7f13\u89e3\u5e7f\u6cdb\u7684\u5185\u5bb9\u6ce8\u5165\u6f0f\u6d1e\uff0c\u6bd4\u5982 XSS\u3002 \u7b80\u5355\u6765\u8bf4\uff0c\u5c31\u662f\u6211\u4eec\u80fd\u591f\u89c4\u5b9a\uff0c\u6211\u4eec\u7684\u7f51\u7ad9\u53ea\u63a5\u53d7\u6211\u4eec\u6307\u5b9a\u7684\u8bf7\u6c42\u8d44\u6e90\u3002\u9ed8\u8ba4\u914d\u7f6e\u4e0b\u4e0d\u5141\u8bb8\u6267\u884c\u5185\u8054\u4ee3\u7801\uff08&lt;script>\u5757\u5185\u5bb9\uff0c\u5185\u8054\u4e8b\u4ef6\uff0c\u5185\u8054\u6837\u5f0f\uff09\uff0c\u4ee5\u53ca\u7981\u6b62\u6267\u884ceval() , new Function() , setTimeout([string], \u2026) \u548csetInterval([string], \u2026) \u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>2.CSP \u4f7f\u7528\u65b9\u5f0f<\/strong><\/h2>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-21c2799905701b603f10d2585ab9b1f0\">CSP\u53ef\u4ee5\u7531\u4e24\u79cd\u65b9\u5f0f\u6307\u5b9a\uff1a HTTP Header \u548c HTML\u3002\u7b56\u7565\u90fd\u662f\u5728\u670d\u52a1\u5668\u7aef\u8bbe\u7f6e\uff0c\u7531\u6d4f\u89c8\u5668\u6267\u884c\u7b56\u7565\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u901a\u8fc7\u5b9a\u4e49\u5728HTTP header \u4e2d\u4f7f\u7528\uff08\u6709\u65f6\u4f60\u4f1a\u770b\u5230 X-Content-Security-Policy \u6807\u5934\uff0c\u4f46\u90a3\u662f\u65e7\u7248\u672c\uff0c\u5e76\u4e14\u4f60\u65e0\u987b\u518d\u5982\u6b64\u6307\u5b9a\u5b83\uff09\uff1a\n<ul class=\"wp-block-list\">\n<li>&#8220;Content-Security-Policy:&#8221; \u7b56\u7565\u96c6<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u901a\u8fc7\u5b9a\u4e49\u5728 HTML meta\u6807\u7b7e\u4e2d\u4f7f\u7528\uff1a\n<ul class=\"wp-block-list\">\n<li>&lt;metahttp-equiv=&#8221;content-security-policy&#8221;content=&#8221;\u7b56\u7565\u96c6&#8221;><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>\u7b56\u7565\u662f\u6307\u5b9a\u4e49 CSP \u7684\u8bed\u6cd5\u5185\u5bb9\u3002\u67d0\u4e9b\u529f\u80fd\uff08\u4f8b\u5982\u53d1\u9001 CSP \u8fdd\u89c4\u62a5\u544a\uff09\u4ec5\u5728\u4f7f\u7528 HTTP \u6807\u5934\u65f6\u53ef\u7528\u3002<\/p>\n\n\n\n<p class=\"has-vivid-red-color has-text-color has-link-color wp-elements-49a31a86a9730da438848777ef9d4341\">\u5982\u679c HTTP \u5934 \u4e0e meta \u6807\u7b7e\u540c\u65f6\u5b9a\u4e49\u4e86 CSP\uff0c\u5219\u4f1a\u4f18\u5148\u91c7\u7528 HTTP \u5934\u7684 \u3002<\/p>\n\n\n\n<p>\u5b9a\u4e49\u540e\uff0c\u51e1\u662f\u4e0d\u7b26\u5408 CSP\u7b56\u7565\u7684\u5916\u90e8\u8d44\u6e90\u90fd\u4f1a\u88ab\u963b\u6b62\u52a0\u8f7d\u3002<\/p>\n\n\n\n<p><strong>2.1&nbsp;\u4ec5\u62a5\u544a\uff08report-only\uff09\u6a21\u5f0f<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp; &nbsp;\u4e3a\u964d\u4f4e\u90e8\u7f72\u6210\u672c\uff0cCSP \u53ef\u4ee5\u90e8\u7f72\u4e3a\u4ec5\u62a5\u544a\uff08report-only\uff09\u6a21\u5f0f\u3002\u5728\u6b64\u6a21\u5f0f\u4e0b\uff0cCSP \u7b56\u7565\u4e0d\u662f\u5f3a\u5236\u6027\u7684\uff0c\u4f46\u662f\u4efb\u4f55\u8fdd\u89c4\u884c\u4e3a\u5c06\u4f1a\u62a5\u544a\u7ed9\u4e00\u4e2a\u6307\u5b9a\u7684 URI \u5730\u5740\u3002\u6b64\u5916\uff0c\u4ec5\u62a5\u544a\u6807\u5934\u53ef\u4ee5\u7528\u6765\u6d4b\u8bd5\u5bf9\u7b56\u7565\u672a\u6765\u7684\u4fee\u8ba2\uff0c\u800c\u4e0d\u7528\u5b9e\u9645\u90e8\u7f72\u5b83\u3002<\/p>\n\n\n\n<p>&nbsp;&nbsp; &nbsp;\u4f60\u53ef\u4ee5\u7528 Content-Security-Policy-Report-Only HTTP \u6807\u5934\u6765\u6307\u5b9a\u4f60\u7684\u7b56\u7565\uff0c\u50cf\u8fd9\u6837\uff1a<\/p>\n\n\n\n<p>Content-Security-Policy-Report-Only: policy<\/p>\n\n\n\n<p>&nbsp;&nbsp; &nbsp;\u5982\u679c Content-Security-Policy-Report-Only \u6807\u5934\u548c Content-Security-Policy \u540c\u65f6\u51fa\u73b0\u5728\u4e00\u4e2a\u54cd\u5e94\u4e2d\uff0c\u4e24\u4e2a\u7b56\u7565\u5747\u6709\u6548\u3002\u5728 Content-Security-Policy \u6807\u5934\u4e2d\u6307\u5b9a\u7684\u7b56\u7565\u6709\u5f3a\u5236\u6027\uff0c\u800c Content-Security-Policy-Report-Only \u4e2d\u7684\u7b56\u7565\u4ec5\u4ea7\u751f\u62a5\u544a\u800c\u4e0d\u5177\u6709\u5f3a\u5236\u6027\u3002<\/p>\n\n\n\n<p>&nbsp;&nbsp; &nbsp;\u652f\u6301 CSP \u7684\u6d4f\u89c8\u5668\u5c06\u59cb\u7ec8\u5bf9\u4e8e\u6bcf\u4e2a\u4f01\u56fe\u8fdd\u53cd\u4f60\u6240\u5efa\u7acb\u7684\u7b56\u7565\u90fd\u53d1\u9001\u8fdd\u89c4\u62a5\u544a\uff0c\u5982\u679c\u7b56\u7565\u91cc\u5305\u542b\u4e00\u4e2a\u6709\u6548\u7684report-uri \u6307\u4ee4\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>3.CSP \u8bed\u6cd5<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3.1 \u7b56\u7565<\/strong><\/h3>\n\n\n\n<p>\u6bcf\u4e00\u6761\u7b56\u7565\u90fd\u662f\u6307\u4ee4\u4e0e\u6307\u4ee4\u503c\u7ec4\u6210\uff1a<\/p>\n\n\n\n<p>Content-Security-Policy:\u6307\u4ee41\u6307\u4ee4\u503c1<\/p>\n\n\n\n<p>\u7b56\u7565\u4e0e\u7b56\u7565\u4e4b\u95f4\u7528\u5206\u53f7\u9694\u5f00,\u4f8b\u5982\uff1a<\/p>\n\n\n\n<p>Content-Security-Policy:\u6307\u4ee41 \u6307\u4ee4\u503c1\uff1b\u6307\u4ee42 \u6307\u4ee4\u503c2\uff1b\u6307\u4ee43 \u6307\u4ee4\u503c3<\/p>\n\n\n\n<p>\u5728\u4e00\u6761\u7b56\u7565\u4e2d\uff0c\u5982\u679c\u4e00\u4e2a\u6307\u4ee4\u4e2d\u6709\u591a\u4e2a\u6307\u4ee4\u503c\uff0c\u5219\u6307\u4ee4\u503c\u4e4b\u95f4\u7528\u7a7a\u53f7\u9694\u5f00\uff1a<\/p>\n\n\n\n<p>Content-Security-Policy:\u6307\u4ee4a \u6307\u4ee4\u503ca1\u6307\u4ee4\u503ca2<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3.2 CSP \u6307\u4ee4<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>default-src : \u5b9a\u4e49\u9488\u5bf9\u6240\u6709\u7c7b\u578b\uff08js\/image\/css\/font\/ajax\/iframe\/\u591a\u5a92\u4f53\u7b49\uff09\u8d44\u6e90\u7684\u9ed8\u8ba4\u52a0\u8f7d\u7b56\u7565\uff0c\u5982\u679c\u67d0\u7c7b\u578b\u8d44\u6e90\u6ca1\u6709\u5355\u72ec\u5b9a\u4e49\u7b56\u7565\uff0c\u5c31\u4f7f\u7528\u9ed8\u8ba4\u7684\u3002<\/li>\n\n\n\n<li>script-src : \u5b9a\u4e49\u9488\u5bf9 JavaScript \u7684\u52a0\u8f7d\u7b56\u7565\u3002<\/li>\n\n\n\n<li>style-src : \u5b9a\u4e49\u9488\u5bf9\u6837\u5f0f\u7684\u52a0\u8f7d\u7b56\u7565\u3002<\/li>\n\n\n\n<li>img-src : \u5b9a\u4e49\u9488\u5bf9\u56fe\u7247\u7684\u52a0\u8f7d\u7b56\u7565\u3002<\/li>\n\n\n\n<li>font-src : \u5b9a\u4e49\u9488\u5bf9\u5b57\u4f53\u7684\u52a0\u8f7d\u7b56\u7565\u3002<\/li>\n\n\n\n<li>media-src : \u5b9a\u4e49\u9488\u5bf9\u591a\u5a92\u4f53\u7684\u52a0\u8f7d\u7b56\u7565\uff0c\u4f8b\u5982:\u97f3\u9891\u6807\u7b7e&lt;audio>\u548c\u89c6\u9891\u6807\u7b7e&lt;video>\u3002<\/li>\n\n\n\n<li>object-src : \u5b9a\u4e49\u9488\u5bf9\u63d2\u4ef6\u7684\u52a0\u8f7d\u7b56\u7565\uff0c\u4f8b\u5982\uff1a&lt;object>\u3001&lt;embed>\u3001&lt;applet>\u3002<\/li>\n\n\n\n<li>child-src :\u5b9a\u4e49\u9488\u5bf9\u6846\u67b6\u7684\u52a0\u8f7d\u7b56\u7565\uff0c\u4f8b\u5982\uff1a\u00a0&lt;frame>,&lt;iframe>\u3002<\/li>\n\n\n\n<li>connect-src : \u5b9a\u4e49\u9488\u5bf9 Ajax\/WebSocket \u7b49\u8bf7\u6c42\u7684\u52a0\u8f7d\u7b56\u7565\u3002\u4e0d\u5141\u8bb8\u7684\u60c5\u51b5\u4e0b\uff0c\u6d4f\u89c8\u5668\u4f1a\u6a21\u62df\u4e00\u4e2a\u72b6\u6001\u4e3a400\u7684\u54cd\u5e94\u3002<\/li>\n\n\n\n<li>sandbox : \u5b9a\u4e49\u9488\u5bf9 sandbox \u7684\u9650\u5236\uff0c\u76f8\u5f53\u4e8e\u00a0&lt;iframe>\u7684sandbox\u5c5e\u6027\u3002<\/li>\n\n\n\n<li>report-uri : \u544a\u8bc9\u6d4f\u89c8\u5668\u5982\u679c\u8bf7\u6c42\u7684\u8d44\u6e90\u4e0d\u88ab\u7b56\u7565\u5141\u8bb8\u65f6\uff0c\u5f80\u54ea\u4e2a\u5730\u5740\u63d0\u4ea4\u65e5\u5fd7\u4fe1\u606f\u3002<\/li>\n\n\n\n<li>form-action : \u5b9a\u4e49\u9488\u5bf9\u63d0\u4ea4\u7684 form \u5230\u7279\u5b9a\u6765\u6e90\u7684\u52a0\u8f7d\u7b56\u7565\u3002<\/li>\n\n\n\n<li>referrer : \u5b9a\u4e49\u9488\u5bf9 referrer \u7684\u52a0\u8f7d\u7b56\u7565\u3002<\/li>\n\n\n\n<li>reflected-xss : \u5b9a\u4e49\u9488\u5bf9 XSS \u8fc7\u6ee4\u5668\u4f7f\u7528\u7b56\u7565\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3.3 CSP \u6307\u4ee4\u503c<\/strong><\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>\u6307\u4ee4\u503c<\/td><td>\u8bf4\u660e<\/td><\/tr><tr><td>*<\/td><td>\u5141\u8bb8\u52a0\u8f7d\u4efb\u4f55\u5185\u5bb9<\/td><\/tr><tr><td>&#8216;none&#8217;<\/td><td>\u4e0d\u5141\u8bb8\u52a0\u8f7d\u4efb\u4f55\u5185\u5bb9<\/td><\/tr><tr><td>&#8216;self&#8217;<\/td><td>\u5141\u8bb8\u52a0\u8f7d\u76f8\u540c\u6e90\u7684\u5185\u5bb9<\/td><\/tr><tr><td>www.a.com<\/td><td>\u5141\u8bb8\u52a0\u8f7d\u6307\u5b9a\u57df\u540d\u7684\u8d44\u6e90<\/td><\/tr><tr><td>*.a.com<\/td><td>\u5141\u8bb8\u52a0\u8f7d a.com \u4efb\u4f55\u5b50\u57df\u540d\u7684\u8d44\u6e90<\/td><\/tr><tr><td>https:\/\/a.com<\/td><td>\u5141\u8bb8\u52a0\u8f7d a.com \u7684 https \u8d44\u6e90<\/td><\/tr><tr><td>https\uff1a<\/td><td>\u5141\u8bb8\u52a0\u8f7d https \u8d44\u6e90<\/td><\/tr><tr><td>data\uff1a<\/td><td>\u5141\u8bb8\u52a0\u8f7d data: \u534f\u8bae\uff0c\u4f8b\u5982\uff1abase64\u7f16\u7801\u7684\u56fe\u7247<\/td><\/tr><tr><td>&#8216;unsafe-inline&#8217;<\/td><td>\u5141\u8bb8\u52a0\u8f7d inline \u8d44\u6e90\uff0c\u4f8b\u5982style\u5c5e\u6027\u3001onclick\u3001inline js\u3001inline css\u7b49<\/td><\/tr><tr><td>&#8216;unsafe-eval&#8217;<\/td><td>\u5141\u8bb8\u52a0\u8f7d\u52a8\u6001 js \u4ee3\u7801\uff0c\u4f8b\u5982 eval()<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>4.CSP \u4f8b\u5b50<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4f8b\u5b501 \n<ul class=\"wp-block-list\">\n<li>\u6240\u6709\u5185\u5bb9\u5747\u6765\u81ea\u7f51\u7ad9\u7684\u81ea\u5df1\u7684\u57df\uff1a\n<ul class=\"wp-block-list\">\n<li>Content-Security-Policy:default-src&#8217;self&#8217;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u4f8b\u5b502\n<ul class=\"wp-block-list\">\n<li> \u6240\u6709\u5185\u5bb9\u90fd\u6765\u81ea\u7f51\u7ad9\u81ea\u5df1\u7684\u57df\uff0c\u8fd8\u6709\u5176\u4ed6\u5b50\u57df\uff08\u5047\u5982\u7f51\u7ad9\u7684\u5730\u5740\u662f\uff1aa.com\uff09\uff1a\n<ul class=\"wp-block-list\">\n<li>Content-Security-Policy:default-src&#8217;self&#8217; *.a.com<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u4f8b\u5b503 \n<ul class=\"wp-block-list\">\n<li>\u7f51\u7ad9\u63a5\u53d7\u4efb\u610f\u57df\u7684\u56fe\u50cf\uff0c\u6307\u5b9a\u57df\uff08a.com\uff09\u7684\u97f3\u9891\u3001\u89c6\u9891\u548c\u591a\u4e2a\u6307\u5b9a\u57df\uff08a.com\u3001b.com\uff09\u7684\u811a\u672c\uff1a\n<ul class=\"wp-block-list\">\n<li>Content-Security-Policy:default-src&#8217;self&#8217;;img-src *;media-src a.com;script-src a.com b.com<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u4f8b\u5b504 \n<ul class=\"wp-block-list\">\n<li>\u6240\u6709\u5185\u5bb9\u90fd\u6765\u81ea\u7f51\u7ad9\u81ea\u5df1\u7684\u57df\uff0c\u8fd8\u6709\u5176\u4ed6https\u5b50\u57df\uff08\u5047\u5982\u7f51\u7ad9\u7684\u5730\u5740\u662f\uff1ahttps:\/\/www.a.com\uff09\uff1a\n<ul class=\"wp-block-list\">\n<li>Content-Security-Policy:default-src&#8217;self&#8217; https:\/\/www.a.com<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5728\u7ebf CSP\u7f16\u5199\u7684\u7f51\u5740\uff1a<a href=\"http:\/\/cspisawesome.com\/\">http:\/\/cspisawesome.com\/<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>5.CSP \u9ed8\u8ba4\u7279\u6027<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u963b\u6b62\u5185\u8054\u4ee3\u7801\u6267\u884c<\/strong>\n<ul class=\"wp-block-list\">\n<li>CSP\u9664\u4e86\u4f7f\u7528\u767d\u540d\u5355\u673a\u5236\u5916\uff0c\u9ed8\u8ba4\u914d\u7f6e\u4e0b\u963b\u6b62\u5185\u8054\u4ee3\u7801\u6267\u884c\u662f\u9632\u6b62\u5185\u5bb9\u6ce8\u5165\u7684\u6700\u5927\u5b89\u5168\u4fdd\u969c\u3002\u8fd9\u91cc\u7684\u5185\u8054\u4ee3\u7801\u5305\u62ec\uff1a&lt;script>\u5757\u5185\u5bb9\uff0c\u5185\u8054\u4e8b\u4ef6\uff0c\u5185\u8054\u6837\u5f0f\u3002<\/li>\n\n\n\n<li>(1) script\u4ee3\u7801\uff0c&lt;script>\u2026\u2026&lt;scritp>\n<ul class=\"wp-block-list\">\n<li>\u5bf9\u4e8e&lt;script>\u5757\u5185\u5bb9\u662f\u5b8c\u5168\u4e0d\u80fd\u6267\u884c\u7684\u3002\u4f8b\u5982\uff1a\n<ul class=\"wp-block-list\">\n<li>&lt;script>getyourcookie()&lt;\/script><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>(2) \u5185\u8054\u4e8b\u4ef6\u3002\n<ul class=\"wp-block-list\">\n<li>&lt;ahref=&#8221;&#8221;onclick=&#8221;handleClick();&#8221;>&lt;\/a><\/li>\n\n\n\n<li>&lt;ahref=&#8221;javascript:handleClick();&#8221;>&lt;\/a><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>(3) \u5185\u8054\u6837\u5f0f\n<ul class=\"wp-block-list\">\n<li>&lt;divstyle=&#8221;display:none&#8221;>&lt;\/div><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u867d\u7136CSP\u4e2d\u5df2\u7ecf\u5bf9script-src\u548cstyle-src\u63d0\u4f9b\u4e86\u4f7f\u7528\u201dunsafe-inline\u201d\u6307\u4ee4\u6765\u5f00\u542f\u6267\u884c\u5185\u8054\u4ee3\u7801\uff0c\u4f46\u4e3a\u4e86\u5b89\u5168\u8d77\u89c1\u8fd8\u662f\u614e\u7528\u201dunsafe-inline\u201d\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>EVAL\u76f8\u5173\u529f\u80fd\u88ab\u7981\u7528<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u7528\u6237\u8f93\u5165\u5b57\u7b26\u4e32\uff0c\u7136\u540e\u7ecf\u8fc7eval()\u7b49\u51fd\u6570\u8f6c\u4e49\u8fdb\u800c\u88ab\u5f53\u4f5c\u811a\u672c\u53bb\u6267\u884c\u3002\u8fd9\u6837\u7684\u653b\u51fb\u65b9\u5f0f\u6bd4\u8f83\u5e38\u89c1\u3002\u4e8e\u662f\u4e4eCSP\u9ed8\u8ba4\u914d\u7f6e\u4e0b\uff0ceval() , new Function() , setTimeout([string], \u2026) \u548csetInterval([string], \u2026)\u90fd\u88ab\u7981\u6b62\u8fd0\u884c\u3002\n<ul class=\"wp-block-list\">\n<li>\u6bd4\u5982\uff1a\n<ul class=\"wp-block-list\">\n<li>alert(eval(&#8220;foo.bar.baz&#8221;));<\/li>\n\n\n\n<li>window.setTimeout(&#8220;alert(&#8216;hi&#8217;)&#8221;, 10); <\/li>\n\n\n\n<li>window.setInterval(&#8220;alert(&#8216;hi&#8217;)&#8221;, 10);<\/li>\n\n\n\n<li>new Function(&#8220;return foo.bar.baz&#8221;);<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u5982\u679c\u60f3\u6267\u884c\u53ef\u4ee5\u628a\u5b57\u7b26\u4e32\u8f6c\u6362\u4e3a\u5185\u8054\u51fd\u6570\u53bb\u6267\u884c\u3002\n<ul class=\"wp-block-list\">\n<li>alert(foo &amp;&amp; foo.bar &amp;&amp; foo.bar.baz);<\/li>\n\n\n\n<li>window.setTimeout(function() { alert(&#8216;hi&#8217;); }, 10);<\/li>\n\n\n\n<li>window.setInterval(function() { alert(&#8216;hi&#8217;); }, 10);<\/li>\n\n\n\n<li>function() { return foo &amp;&amp; foo.bar &amp;&amp; foo.bar.baz };<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u540c\u6837CSP\u4e5f\u63d0\u4f9b\u4e86\u201dunsafe-eval\u201d\u53bb\u5f00\u542f\u6267\u884ceval()\u7b49\u51fd\u6570\uff0c\u4f46\u5f3a\u70c8\u4e0d\u5efa\u8bae\u53bb\u4f7f\u7528\u201dunsafe-eval\u201d\u8fd9\u4e2a\u6307\u4ee4\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>6.CSP \u5206\u6790\u62a5\u544a<\/strong><\/h2>\n\n\n\n<p>\u53ef\u4ee5\u7528report-uri\u6307\u4ee4\u4f7f\u6d4f\u89c8\u5668\u53d1\u9001HTTP POST\u8bf7\u6c42\u628a\u653b\u51fb\u62a5\u544a\u4ee5JSON\u683c\u5f0f\u4f20\u9001\u5230\u4f60\u6307\u5b9a\u7684\u5730\u5740\u3002\u63a5\u4e0b\u6765\u7ed9\u5927\u5bb6\u4ecb\u7ecd\u4f60\u7684\u7ad9\u70b9\u5982\u4f55\u914d\u7f6e\u6765\u63a5\u6536\u653b\u51fb\u62a5\u544a\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u542f\u7528\u62a5\u544a<\/strong>\n<ul class=\"wp-block-list\">\n<li>\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8fdd\u89c4\u62a5\u544a\u4e0d\u4f1a\u53d1\u9001\u3002\u4e3a\u4e86\u80fd\u4f7f\u7528\u8fdd\u89c4\u62a5\u544a\uff0c\u4f60\u5fc5\u987b\u4f7f\u7528report-uri\u6307\u4ee4\uff0c\u5e76\u81f3\u5c11\u63d0\u4f9b\u4e00\u4e2a\u63a5\u6536\u5730\u5740\u3002<\/li>\n\n\n\n<li>Content-Security-Policy:default-srcself; report-uri http:\/\/reportcollector.example.com\/collector.cgi<\/li>\n\n\n\n<li>\u5982\u679c\u60f3\u8ba9\u6d4f\u89c8\u5668\u53ea\u6c47\u62a5\u62a5\u544a\uff0c\u4e0d\u963b\u6b62\u4efb\u4f55\u5185\u5bb9\uff0c\u53ef\u4ee5\u6539\u7528Content-Security-Policy-Report-Only\u5934\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8fdd\u89c4\u62a5\u544a\u8bed\u6cd5<\/strong>\uff0c\n<ul class=\"wp-block-list\">\n<li>\u8be5\u62a5\u544aJSON\u5bf9\u8c61\u5305\u542b\u4ee5\u4e0b\u6570\u636e\uff1a<\/li>\n\n\n\n<li>blocked-uri\uff1a\u88ab\u963b\u6b62\u7684\u8fdd\u89c4\u8d44\u6e90<\/li>\n\n\n\n<li>document-uri\uff1a\u62e6\u622a\u8fdd\u89c4\u884c\u4e3a\u53d1\u751f\u7684\u9875\u9762<\/li>\n\n\n\n<li>original-policy\uff1aContent-Security-Policy\u5934\u7b56\u7565\u7684\u6240\u6709\u5185\u5bb9<\/li>\n\n\n\n<li>referrer\uff1a\u9875\u9762\u7684referrer<\/li>\n\n\n\n<li>status-code\uff1aHTTP\u54cd\u5e94\u72b6\u6001<\/li>\n\n\n\n<li>violated-directive\uff1a\u8fdd\u89c4\u7684\u6307\u4ee4<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u8fdd\u89c4\u62a5\u544a\u4f8b\u5b50<\/strong>\n<ul class=\"wp-block-list\">\n<li>http:\/\/example.com\/signup.html\u00a0\u4e2dCSP \u89c4\u5b9a\u53ea\u80fd\u52a0\u8f7dcdn.example.com\u7684CSS\u6837\u5f0f\u3002<\/li>\n\n\n\n<li>Content-Security-Policy:default-src&#8217;none&#8217;; style-src cdn.example.com;report-uri \/test\/csp-report.php<\/li>\n\n\n\n<li>signup.html\u4e2d\u7684\u4ee3\u7801\u7c7b\u4f3c\u4e0e\u8fd9\u6837\uff1a\n<ul class=\"wp-block-list\">\n<li>&lt;!DOCTYPEhtml><\/li>\n\n\n\n<li>&lt;html><\/li>\n\n\n\n<li>&lt;head><\/li>\n\n\n\n<li>&lt;title>Sign Up&lt;\/title><\/li>\n\n\n\n<li>&lt;linkrel=&#8221;stylesheet&#8221;href=&#8221;css\/style.css&#8221;><\/li>\n\n\n\n<li>&lt;\/head><\/li>\n\n\n\n<li>&lt;body>&#8230; Content &#8230;&lt;\/body><\/li>\n\n\n\n<li>&lt;\/html><\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u4f60\u80fd\u4ece\u4e0a\u9762\u7684\u4ee3\u7801\u627e\u51fa\u9519\u8bef\u5417\uff1f\u7b56\u7565\u662f\u53ea\u5141\u8bb8\u52a0\u8f7dcdn.example.com\u4e2d\u7684CSS\u6837\u5f0f\u3002\u4f46signup.html\u8bd5\u56fe\u52a0\u8f7d\u81ea\u5df1\u57df\u7684style.css\u6837\u5f0f\u3002\u8fd9\u6837\u8fdd\u53cd\u4e86\u7b56\u7565\uff0c\u6d4f\u89c8\u5668\u4f1a\u5411\u00a0http:\/\/example.com\/test\/csp-report.php\u00a0\u53d1\u9001POST\u8bf7\u6c42\u63d0\u4ea4\u62a5\u544a\uff0c\u53d1\u9001\u683c\u5f0f\u4e3aJSON\u683c\u5f0f\u3002\n<ul class=\"wp-block-list\">\n<li>{&#8220;csp-report&#8221;: {\n<ul class=\"wp-block-list\">\n<li>&#8220;document-uri&#8221;: &#8220;http:\/\/example.com\/signup.html&#8221;,<\/li>\n\n\n\n<li>&#8220;referrer&#8221;: &#8220;&#8221;,<\/li>\n\n\n\n<li>&#8220;blocked-uri&#8221;: &#8220;http:\/\/example.com\/css\/style.css&#8221;,<\/li>\n\n\n\n<li>&#8220;violated-directive&#8221;: &#8220;style-src cdn.example.com&#8221;,<\/li>\n\n\n\n<li>&#8220;original-policy&#8221;: &#8220;default-src &#8216;none&#8217;; style-src cdn.example.com; report-uri \/_\/csp-reports&#8221;,<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>}}<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>\u4f60\u4ece\u4e0a\u9762\u53ef\u4ee5\u770b\u5230blocked-uri\u7ed9\u51fa\u4e86\u8be6\u7ec6\u7684\u963b\u65ad\u5730\u5740\u00a0http:\/\/example.com\/css\/style.css\uff0c\u4f46\u4e5f\u5e76\u4e0d\u662f\u6bcf\u6b21\u90fd\u662f\u8fd9\u6837\u3002\u6bd4\u5982\u8bd5\u56fe\u4ece\u00a0http:\/\/anothercdn.example.com\/stylesheet.css\u00a0\u52a0\u8f7dCSS\u6837\u5f0f\u65f6\uff0c\u6d4f\u89c8\u5668\u5c06\u4e0d\u4f1a\u4f20\u9001\u5b8c\u6574\u7684\u8def\u5f84\uff0c\u53ea\u4f1a\u7ed9\u51fa\u00a0http:\/\/anothercdn.example.com\/\u00a0\u8fd9\u4e2a\u5730\u5740\u3002\u8fd9\u6837\u505a\u662f\u4e3a\u4e86\u9632\u6b62\u6cc4\u6f0f\u8de8\u57df\u7684\u654f\u611f\u4fe1\u606f\u3002<\/li>\n\n\n\n<li>\u670d\u52a1\u7aefcsp-report.php\u4ee3\u7801\u53ef\u4ee5\u8fd9\u6837\u5199\uff1a\n<ul class=\"wp-block-list\">\n<li>&lt;?php<\/li>\n\n\n\n<li>$file = fopen(&#8216;csp-report.txt&#8217;, &#8216;a&#8217;);<\/li>\n\n\n\n<li>$json = file_get_contents(&#8216;php:\/\/input&#8217;);<\/li>\n\n\n\n<li>$csp = json_decode($json, true);<\/li>\n\n\n\n<li>foreach ($csp[&#8216;csp-report&#8217;] as$key => $val) {\n<ul class=\"wp-block-list\">\n<li>fwrite($file, $key . &#8216;: &#8216; . $val . &#8220;&#8221;);<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>}<\/li>\n\n\n\n<li>fwrite($file, &#8216;End of report.&#8217; . &#8220;&#8221;);<\/li>\n\n\n\n<li>fclose($file);<\/li>\n\n\n\n<li>?><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>7.\u517c\u5bb9\u6027\u5907\u6ce8<\/strong><\/p>\n\n\n\n<p>&nbsp;&nbsp; &nbsp;\u5728\u67d0\u4e9b\u7248\u672c\u7684 Safari \u7f51\u7edc\u6d4f\u89c8\u5668\u4e2d\u5b58\u5728\u4e00\u79cd\u7279\u6b8a\u7684\u4e0d\u517c\u5bb9\u6027\uff0c\u5373\u5982\u679c\u8bbe\u7f6e\u4e86\u5185\u5bb9\u5b89\u5168\u7b56\u7565\u6807\u5934\uff0c\u4f46\u6ca1\u6709\u8bbe\u7f6e\u76f8\u540c\u6765\u6e90\uff08Same Origin\uff09\u6807\u5934\u3002\u6d4f\u89c8\u5668\u5c06\u963b\u6b62\u81ea\u6211\u6258\u7ba1\u7684\u5185\u5bb9\u548c\u7f51\u7ad9\u5916\u7684\u5185\u5bb9\uff0c\u5e76\u9519\u8bef\u5730\u62a5\u544a\u8bf4\u8fd9\u662f\u7531\u4e8e\u5185\u5bb9\u5b89\u5168\u653f\u7b56\u4e0d\u5141\u8bb8\u8be5\u5185\u5bb9\u3002<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1.CSP \u7b80\u4ecb \u00a0\u00a0 \u00a0\u5185\u5bb9\u5b89\u5168\u7b56\u7565\uff08Content Security Policy\uff0c\u7b80\u79f0CSP\uff09\u662f\u4e00\u79cd\u4ee5\u53ef &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[186,14],"tags":[925,923,928,926,924,927],"class_list":["post-1179","post","type-post","status-publish","format-standard","hentry","category-186","category-14","tag-content-security-policy","tag-csp","tag-script-src","tag-xss","tag-924","tag-927"],"views":903,"_links":{"self":[{"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1179","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1179"}],"version-history":[{"count":1,"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1179\/revisions"}],"predecessor-version":[{"id":1180,"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1179\/revisions\/1180"}],"wp:attachment":[{"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1179"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1179"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.max-shu.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1179"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}