Skip to content

security(csp): version-safe inline-script nonce wrapper + strengthen PO/MO instructions - #27

Merged
TheWitness merged 2 commits into
mainfrom
feature/csp-nonce-inline-js
Sep 28, 2026
Merged

TheWitness merged 2 commits into
mainfrom
feature/csp-nonce-inline-js

Conversation

@TheWitness

Copy link
Copy Markdown
Member

Summary

Part of the fleet-wide CSP-nonce rollout (mirrors the pilot Cacti/plugin_mactrack#374).

  1. Version-safe CSP nonce on inline JavaScript. Adds a wrapper
    plugin_<name>_csp_nonce() and applies it to every inline <script> block, so
    pages stay compatible with Cacti's Content-Security-Policy nonce enforcement.
  2. Strengthened i18n instruction in .github/copilot-instructions.md — the
    .po/.mo files are never committed (Weblate owns them); only cacti.pot.

Wrapper (cross-version safe)

function plugin_<name>_csp_nonce(): string {
	if (class_exists('CactiSecureHeaders')) {
		return CactiSecureHeaders::getNonceAttribute();
	}

	return '';
}

Emits the per-request nonce="..." on Cacti releases that ship CactiSecureHeaders
(present on both develop and 1.2.x), and '' on older releases — so the tag
stays valid either way. The wrapper lives in the plugin's functions library where one
exists, otherwise in setup.php (loaded on every Cacti page by the plugin loader).

Also

  • tests/Unit/CspNonceTest.php covers the empty-string fallback, the string
    return type, and delegation to CactiSecureHeaders.
  • Where the plugin emits its own external <script src> / CSS <link>, those go
    through Cacti's get_md5_include_js() / get_md5_include_css() helpers (automatic
    nonce + md5 cache-buster).
  • locales/po/cacti.pot regenerated for shifted source line references; the
    per-language .po/.mo catalogs are intentionally not committed.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical CSP integration and test issues remain unresolved.

Review effort: Lite
Findings: 2 High severity · 1 Low severity

Open (3)
What changed in this PR

Adds version-safe CSP nonce support for QuickTree inline scripts and strengthens translation catalog handling.

Changes:

  • Adds CSP nonce helper and updated asset inclusion.
  • Adds nonce tests and refreshes POT references.
  • Updates changelog and PO/MO guidance.
File Review findings
tests/​Unit/​CspNonceTest.php Critical (1 vote): Fallback assertion fails when CactiSecureHeaders exists; also affects line 27.
setup.php Nit (2 votes): Rename the helper to quicktree_csp_nonce() to match naming conventions.
quicktree.php Critical (4 votes): Nonce concatenation is outside PHP mode and is emitted literally, so CSP blocks the script.
locales/​po/​cacti.pot Updated generated source references.
CHANGELOG.md Documents the CSP change.
.github/​copilot-instructions.md Strengthens PO/MO catalog handling guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread quicktree.php Outdated
Comment thread tests/Unit/CspNonceTest.php Outdated
Comment thread setup.php
@TheWitness
TheWitness merged commit 167ef6e into main Sep 28, 2026
5 checks passed
@TheWitness
TheWitness deleted the feature/csp-nonce-inline-js branch September 28, 2026 12:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants