FRONTEND CONFERENCE 2017 ã«ã¦ã - ãªã¢ã¼ããã¼ã ã§ç¤¾å ããã«ã½ã³ããã£ãã¨ãã½ã¼ã - ãã®æã«ä½¿ã£ãããã³ãæè¡ã®ç´¹ä» ãçºè¡¨ããæã®è³æã§ãã
FRONTEND CONFERENCE 2017 ã«ã¦ã - ãªã¢ã¼ããã¼ã ã§ç¤¾å ããã«ã½ã³ããã£ãã¨ãã½ã¼ã - ãã®æã«ä½¿ã£ãããã³ãæè¡ã®ç´¹ä» ãçºè¡¨ããæã®è³æã§ãã
HTML5ã§å°å ¥ãããiframeè¦ç´ ã®sandboxå±æ§ã¯ããã®iframeå ã®ã³ã³ãã³ãã«å¯¾ãJavaScriptã®å®è¡ãå§ãæ§ã ãªå¶ç´ã課ããã¨ã§ã»ãã¥ãªãã£ã®åä¸ã«å½¹ç«ã¤æ©è½ã§ãããä¾ãã°ã以ä¸ã®ããã«æå®ãããiframeã§ã¯ãiframeå ããformã®submitãªã©ã¯ã§ããããiframeå ã§ã®JavaScriptã®å®è¡ãtarget=_blankãªã©ã«ãã£ã¦ã¦ã£ã³ãã¦ãéããã¨ãªã©ã¯ç¦æ¢ãããã <iframe sandbox="allow-forms" src="..."></iframe> sandboxå±æ§ã«æ示çã« allow-scripts ã¨ããå¤ãæå®ããªãéãã¯iframeå ã§ã¯ç´æ¥çã«ã¯JavaScriptã¯å®è¡ã§ããªããããã¨ãã£ã¦iframeå ããéæ¥çã«JavaScriptãå¿ ãããå®è¡ããããã¨ãä¸å¯è½ãã¨ããã¨ããã§ããªãã sandboxå±æ§
ãã®ãã¡ããå°ããã¡ãã¨æ¸ãã¾ãããã¨ããããæéããªãã®ã§çµè«ã ãæ¸ãã¨ãã¿ã¤ãã«ãå ¨ã¦ã§Electronã§ã¢ããªãæ¸ãå ´åã¯æ°åãã¨æ ¹æ§ã§XSSãçºçãããªãããã«ããªããã°ãªããªãã ããã¾ã§Webã¢ããªã±ã¼ã·ã§ã³ä¸ã§XSSãåå¨ããã¨ãã¦ããå½±é¿ç¯å²ã¯ãã®Webã¢ããªã±ã¼ã·ã§ã³ã®ä¸ã«çã¾ãã®ã§ãWebã¢ããªã±ã¼ã·ã§ã³ã®æä¾å´ãããã許容ããã®ã§ããã°XSSã®åå¨ã«ç®ãã¤ãããã¨ãã§ãããããããElectronã¢ããªã§DOM-based XSSãä¸ãæã§ãçºçããã¨ã(ãããã)確å®ã«ä»»æã³ã¼ãå®è¡ã¸ã¨ã¤ãªãããå©ç¨è ã®PCã®(ãã®ã¦ã¼ã¶ã¼æ¨©éã§ã®)å ¨æ©è½ãæ»æè ã«ãã£ã¦å©ç¨ã§ããã ãã®ãããElectronã§ã¢ããªã±ã¼ã·ã§ã³ãä½æããéçºè ã¯æ°åãã¨æ ¹æ§ã§XSSãå®å ¨ã«ã¤ã¶ããªããã°ãªããªãã nodeIntegration:falseãContent-Security-Pol
1. This results in a 30% performance hit. It is unclear if it is supported in version 0.13. 2. This is a very weak protection. Itâs basically a TAR archive of all the project files. 3. On a MacBook Pro Retina running Mac OS X.5.5 (Yosemite). Higher is better. 4. Unzipped. Depending on platform and architecture. See details in Jaredâs comment below. 5. This can be done by using the ânode-mainâ inst
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}