Skip to content

docs UI (Scalar/Swagger) loads CDN scripts without pinned version or SRI #226

Description

@ZhuchkaTriplesix

Where: oxyroute/docs_ui.py:51 (Scalar: https://cdn.jsdelivr.net/npm/@scalar/api-reference, no version pin), :65,:70 (Swagger UI: pinned to major version @5 only, no integrity/crossorigin attribute on either).

If the CDN or the npm package is compromised, the docs page executes arbitrary JS in the API's origin — worse for Scalar since it has no version pin at all, so a malicious/broken publish is served immediately with no way to pin a known-good version.

Fix direction: pin exact versions for both, add Subresource Integrity (integrity/crossorigin="anonymous") hashes for the pinned versions, and consider allowing self-hosted assets as an alternative to CDN loading.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions