Skip to content

2026.10.16 — 2026-10-06 ​

Breaking ​

  • Enforce Trusted Types and send the full set of security headers (9fe0fec5)

    Every response (the app, its static files, API answers and error responses) now carries:

    • Content-Security-Policy with three more directives: script-src-attr 'none' (an inline event handler never runs), require-trusted-types-for 'script' (the DOM's markup and script sinks take only Trusted Types values) and trusted-types default dompurify studio#worker (the only policies the page may create).
    • Referrer-Policy: no-referrer.
    • Permissions-Policy turning off camera, microphone, geolocation, payment, USB and the other sensors.
    • Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin.
    • X-Content-Type-Options: nosniff and X-Frame-Options: DENY, as before. HSTS is still sent over HTTPS only.

    The exported broker.xml fragment is now sent as an attachment (broker-config.xml), so a browser sent to its address saves it instead of rendering it. The interface fetches it as before.

Security ​

  • Enforce Trusted Types and send the full set of security headers (9fe0fec5)

    Every response (the app, its static files, API answers and error responses) now carries:

    • Content-Security-Policy with three more directives: script-src-attr 'none' (an inline event handler never runs), require-trusted-types-for 'script' (the DOM's markup and script sinks take only Trusted Types values) and trusted-types default dompurify studio#worker (the only policies the page may create).
    • Referrer-Policy: no-referrer.
    • Permissions-Policy turning off camera, microphone, geolocation, payment, USB and the other sensors.
    • Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Resource-Policy: same-origin.
    • X-Content-Type-Options: nosniff and X-Frame-Options: DENY, as before. HSTS is still sent over HTTPS only.

    The exported broker.xml fragment is now sent as an attachment (broker-config.xml), so a browser sent to its address saves it instead of rendering it. The interface fetches it as before.

  • Keep strings from becoming markup or script in the browser (7ea0e012)

    The interface now holds itself to the Trusted Types policy the server enforces: nothing writes a string to a markup or script sink. What changed for operators and for people who build on Studio:

    • Highlighted code (message bodies, headers and configuration shown with syntax colours) is the only HTML the interface renders. It now passes through DOMPurify, which keeps only <span> elements with a class and a style, before it reaches the page.
    • The layout worker for the topology and flow diagrams gets its script URL from a named policy that refuses any URL outside Studio's origin.
    • Links built from data (a plugin's vendor link and icon, an identity provider's start path, the bug-report link) go through safeHref, which allows only http:, https:, mailto: and Studio's own address, so a javascript: or data: value is never a link.
    • The lint rules now fail the build on dangerouslySetInnerHTML, assignment to innerHTML or outerHTML, insertAdjacentHTML, document.write, eval, new Function, a string passed to setTimeout or setInterval, and javascript: addresses.
    • The browser test project runs with Trusted Types enforced, so a sink that takes a string fails a test the way it would fail for a viewer.

Apache-2.0. Apache ActiveMQ and Apache ActiveMQ Artemis are trademarks of the Apache Software Foundation. Artemis Studio is an independent project, not produced by, endorsed by, or affiliated with the ASF.