Repository navigation
fix: sandbox served course assets to prevent stored XSS - #94
Merged
johanseto merged 1 commit intoSep 29, 2026
Merged
Conversation
Studio course assets are served by the contentserver with the uploader-supplied Content-Type and no neutralizing headers, on a route mounted on the Studio (CMS) origin. An author with file-upload permission can upload an HTML or SVG file containing script; when another user opens the asset URL it runs same-origin with the Studio session, enabling privilege escalation (self-granting course-admin, or Django superuser via same-origin /admin/ when a global-staff user views it). Send `Content-Security-Policy: sandbox` on every course-asset response so the asset loads in an opaque origin and cannot script against the Studio/LMS session. A per-course escape-hatch flag, course_assets.allow_unsafe_asset_rendering, lets operators temporarily disable sandboxing for a course whose content must be migrated first. Closes GHSA-c6xg-fh3c-vvhh. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> (cherry picked from commit b5fc56a)
|
@johanseto did you include this in the doc ? |
Author
https://github.com/eduNEXT/edunext-nelp-documentation/pull/31 |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request introduces a security improvement to the way course assets are served by the contentserver, ensuring that uploaded assets such as HTML or SVG files are sandboxed by default to prevent cross-site scripting (XSS) attacks. It also adds a new feature flag,
course_assets.allow_unsafe_asset_rendering, which allows this sandboxing to be disabled globally or on a per-course basis for exceptional cases. The changes are covered by new tests to verify the correct behavior of the sandbox header under different flag configurations.Security improvements:
Content-Security-Policy: sandboxheader, preventing uploaded assets from executing scripts in the Studio/LMS origin and mitigating stored XSS risks.Feature flag introduction:
course_assets.allow_unsafe_asset_renderingfeature flag (aCourseWaffleFlag) with documentation, allowing the sandboxing protection to be selectively disabled for specific courses or globally if necessary.Testing and validation:
override_waffle_flag,CourseKey, andWaffleFlagCourseOverrideModel.Test
Before
After