2026.10.16 — 2026-10-06
Breaking
Enforce Trusted Types and send the full set of security headers (9fe0fec5)
Every response (the app, its static files, API answers and error responses) now carries:
Content-Security-Policywith three more directives:script-src-attr 'none'(an inline event handler never runs),require-trusted-types-for 'script'(the DOM's markup and script sinks take only Trusted Types values) andtrusted-types default dompurify studio#worker(the only policies the page may create).Referrer-Policy: no-referrer.Permissions-Policyturning off camera, microphone, geolocation, payment, USB and the other sensors.Cross-Origin-Opener-Policy: same-originandCross-Origin-Resource-Policy: same-origin.X-Content-Type-Options: nosniffandX-Frame-Options: DENY, as before. HSTS is still sent over HTTPS only.
The exported
broker.xmlfragment is now sent as an attachment (broker-config.xml), so a browser sent to its address saves it instead of rendering it. The interface fetches it as before.
Security
Enforce Trusted Types and send the full set of security headers (9fe0fec5)
Every response (the app, its static files, API answers and error responses) now carries:
Content-Security-Policywith three more directives:script-src-attr 'none'(an inline event handler never runs),require-trusted-types-for 'script'(the DOM's markup and script sinks take only Trusted Types values) andtrusted-types default dompurify studio#worker(the only policies the page may create).Referrer-Policy: no-referrer.Permissions-Policyturning off camera, microphone, geolocation, payment, USB and the other sensors.Cross-Origin-Opener-Policy: same-originandCross-Origin-Resource-Policy: same-origin.X-Content-Type-Options: nosniffandX-Frame-Options: DENY, as before. HSTS is still sent over HTTPS only.
The exported
broker.xmlfragment is now sent as an attachment (broker-config.xml), so a browser sent to its address saves it instead of rendering it. The interface fetches it as before.Keep strings from becoming markup or script in the browser (7ea0e012)
The interface now holds itself to the Trusted Types policy the server enforces: nothing writes a string to a markup or script sink. What changed for operators and for people who build on Studio:
- Highlighted code (message bodies, headers and configuration shown with syntax colours) is the only HTML the interface renders. It now passes through DOMPurify, which keeps only
<span>elements with a class and a style, before it reaches the page. - The layout worker for the topology and flow diagrams gets its script URL from a named policy that refuses any URL outside Studio's origin.
- Links built from data (a plugin's vendor link and icon, an identity provider's start path, the bug-report link) go through
safeHref, which allows onlyhttp:,https:,mailto:and Studio's own address, so ajavascript:ordata:value is never a link. - The lint rules now fail the build on
dangerouslySetInnerHTML, assignment toinnerHTMLorouterHTML,insertAdjacentHTML,document.write,eval,new Function, a string passed tosetTimeoutorsetInterval, andjavascript:addresses. - The browser test project runs with Trusted Types enforced, so a sink that takes a string fails a test the way it would fail for a viewer.
- Highlighted code (message bodies, headers and configuration shown with syntax colours) is the only HTML the interface renders. It now passes through DOMPurify, which keeps only