Commit ed90fd8
authored
Disable specific localstorage access at runtime (#1079)
Accessing localstorage (eg. `localstorage.getItem('authKey')`) is a
potential security risk when running code that has been shared between
individuals / is untrusted.
This change overrides the specific localstorage method / key access and
provides feedback in the browser console.
Access to localstorage is not entirely blocked as it is used in many
projects / resources eg. [Share Your
World](https://projects.raspberrypi.org/en/projects/share-your-world)
(https://github.com/search?q=repo%3Araspberrypilearning%2Fshare-your-world%20localstorage&type=code)
For more context, see:
https://github.com/RaspberryPiFoundation/documentation/pull/112/files
***
The change can be tested by creating a new HTML project in the editor,
inputting the following and inspecting the console for the output:
```
<script>
localStorage.setItem("foo", "bar")
console.log(localStorage.getItem("foo"))
localStorage.setItem("authKey", "secret")
console.log(localStorage.getItem("authKey"))
</script>
```
As demonstrated here:
1 parent 19b74d7 commit ed90fd8
File tree
5 files changed
+163
-28
lines changed- cypress/e2e
- src/components/Editor/Runners/HtmlRunner
5 files changed
+163
-28
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
7 | 13 | | |
8 | 14 | | |
9 | 15 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
59 | | - | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
60 | 64 | | |
61 | 65 | | |
62 | 66 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
23 | 63 | | |
24 | 64 | | |
25 | 65 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
297 | 297 | | |
298 | 298 | | |
299 | 299 | | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
300 | 349 | | |
301 | 350 | | |
302 | 351 | | |
| |||
Lines changed: 63 additions & 27 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
273 | 273 | | |
274 | 274 | | |
275 | 275 | | |
276 | | - | |
277 | | - | |
278 | | - | |
279 | | - | |
280 | | - | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
281 | 280 | | |
282 | 281 | | |
283 | 282 | | |
284 | 283 | | |
285 | 284 | | |
286 | 285 | | |
287 | 286 | | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
288 | 307 | | |
289 | 308 | | |
290 | 309 | | |
291 | 310 | | |
292 | 311 | | |
293 | 312 | | |
294 | | - | |
295 | 313 | | |
296 | 314 | | |
297 | 315 | | |
| |||
326 | 344 | | |
327 | 345 | | |
328 | 346 | | |
329 | | - | |
330 | | - | |
331 | | - | |
332 | | - | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
333 | 356 | | |
334 | 357 | | |
335 | 358 | | |
336 | 359 | | |
337 | 360 | | |
338 | 361 | | |
339 | 362 | | |
340 | | - | |
341 | 363 | | |
342 | 364 | | |
343 | 365 | | |
| |||
373 | 395 | | |
374 | 396 | | |
375 | 397 | | |
376 | | - | |
377 | | - | |
378 | | - | |
379 | | - | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
380 | 408 | | |
381 | 409 | | |
382 | 410 | | |
383 | 411 | | |
384 | 412 | | |
385 | | - | |
386 | 413 | | |
387 | 414 | | |
388 | 415 | | |
| |||
417 | 444 | | |
418 | 445 | | |
419 | 446 | | |
420 | | - | |
421 | | - | |
422 | | - | |
423 | | - | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
424 | 456 | | |
425 | 457 | | |
426 | 458 | | |
427 | 459 | | |
428 | 460 | | |
429 | | - | |
430 | | - | |
431 | | - | |
432 | 461 | | |
433 | 462 | | |
434 | 463 | | |
| |||
456 | 485 | | |
457 | 486 | | |
458 | 487 | | |
459 | | - | |
460 | | - | |
461 | | - | |
462 | | - | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
463 | 499 | | |
464 | 500 | | |
465 | 501 | | |
| |||
0 commit comments