Skip to content

security(csp): version-safe inline-script nonce wrapper + strengthen PO/MO instructions - #272

Merged
TheWitness merged 2 commits into
developfrom
feature/csp-nonce-inline-js
Sep 28, 2026
Merged

TheWitness merged 2 commits into
developfrom
feature/csp-nonce-inline-js

Conversation

@TheWitness

Copy link
Copy Markdown
Member

Summary

Part of the fleet-wide CSP-nonce rollout (mirrors the pilot Cacti/plugin_mactrack#374).

  1. Version-safe CSP nonce on inline JavaScript. Adds a wrapper
    plugin_<name>_csp_nonce() and applies it to every inline <script> block, so
    pages stay compatible with Cacti's Content-Security-Policy nonce enforcement.
  2. Strengthened i18n instruction in .github/copilot-instructions.md — the
    .po/.mo files are never committed (Weblate owns them); only cacti.pot.

Wrapper (cross-version safe)

function plugin_<name>_csp_nonce(): string {
	if (class_exists('CactiSecureHeaders')) {
		return CactiSecureHeaders::getNonceAttribute();
	}

	return '';
}

Emits the per-request nonce="..." on Cacti releases that ship CactiSecureHeaders
(present on both develop and 1.2.x), and '' on older releases — so the tag
stays valid either way. The wrapper lives in the plugin's functions library where one
exists, otherwise in setup.php (loaded on every Cacti page by the plugin loader).

Also

  • tests/Unit/CspNonceTest.php covers the empty-string fallback, the string
    return type, and delegation to CactiSecureHeaders.
  • Where the plugin emits its own external <script src> / CSS <link>, those go
    through Cacti's get_md5_include_js() / get_md5_include_css() helpers (automatic
    nonce + md5 cache-buster).
  • locales/po/cacti.pot regenerated for shifted source line references; the
    per-language .po/.mo catalogs are intentionally not committed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Isolate the fallback test from global bootstrap state so it remains valid when CactiSecureHeaders is loaded.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds version-safe CSP nonce support for FlowView inline scripts and strengthens PO/MO handling guidance.

Changes:

  • Adds and applies a CSP nonce wrapper.
  • Uses Cacti include helpers for CSS and JavaScript assets.
  • Adds nonce tests and updates translation references and documentation.
File Description
tests/​Unit/​CspNonceTest.php Adds CSP nonce tests; fallback coverage should be isolated from bootstrap-loaded classes.
setup.php Adds the nonce wrapper and include helper usage.
locales/​po/​cacti.pot Updates generated source references.
functions.php Adds nonces to inline scripts.
flowview_schedules.php Adds nonces to page scripts.
flowview_filters.php Adds nonces to page scripts.
flowview_devices.php Adds nonces to page scripts.
flowview_databases.php Adds nonces to page scripts.
CHANGELOG.md Documents the security change.
.github/​copilot-instructions.md Clarifies PO/MO catalog ownership.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/Unit/CspNonceTest.php Outdated
@TheWitness
TheWitness merged commit e876911 into develop Sep 28, 2026
3 checks passed
@TheWitness
TheWitness deleted the feature/csp-nonce-inline-js branch September 28, 2026 12:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants