Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.javascript > #38966 > unrolled thread

Chrome and passing on cross-origin

Started bydoctor@doctor.nl2k.ab.ca (The Doctor)
First post2020-10-17 02:59 +0000
Last post2020-10-20 09:47 -0700
Articles 16 on this page of 36 — 4 participants

Back to article view | Back to comp.lang.javascript


Contents

  Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-17 02:59 +0000
    Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-16 21:45 -0700
      Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-17 11:00 +0200
      Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-17 13:24 +0000
        Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-17 22:27 +0000
          Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-17 17:30 -0700
            Re: Chrome and passing on cross-origin "J.O. Aho" <user@example.net> - 2020-10-18 16:14 +0200
            Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-18 10:17 -0700
              Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-18 22:15 +0000
                Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-18 15:31 -0700
                  Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-19 00:54 +0000
                    Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-18 18:51 -0700
                      Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-19 02:43 +0000
                        Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-18 19:48 -0700
                          Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-19 21:58 +0000
                            Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-19 21:11 -0700
                              Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-20 05:04 +0000
                                Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-20 13:14 +0000
                                  Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-20 09:47 -0700
                                    Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-21 13:59 +0000
                                      Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-22 13:41 +0000
                                        Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-22 11:46 -0700
                                          Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-22 22:36 +0000
                                            Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-24 02:42 +0000
                                              Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-24 14:47 -0700
                                                Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-25 00:05 +0200
                                                  Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-24 15:24 -0700
                                                    Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-25 00:53 +0200
                                                      Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-24 23:42 +0000
                                                      Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-24 21:19 -0700
                                                        Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-25 15:33 +0100
                                                          Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-25 18:49 +0000
                                                            Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-25 12:04 -0700
                                                              Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-26 00:31 +0100
                                                              Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-26 00:44 +0000
                                Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-20 09:47 -0700

Page 2 of 2 — ← Prev page 1 [2]


#39030

Fromdoctor@doctor.nl2k.ab.ca (The Doctor)
Date2020-10-22 13:41 +0000
Message-ID<rms26o$1fch$1@gallifrey.nk.ca>
In reply to#39022
In article <rmpert$1qts$3@gallifrey.nk.ca>,
The Doctor <doctor@doctor.nl2k.ab.ca> wrote:
>In article <457449fa-50ef-4d27-994c-14751ed6ebf9n@googlegroups.com>,
>Michael Haufe (TNO) <tno@thenewobjective.com> wrote:
>>On Tuesday, October 20, 2020 at 8:14:35 AM UTC-5, The Doctor wrote:
>>
>>> Indicate whether to send a cookie in a cross-site request by
>>specifying its SameSite attribute 
>>> 
>>> How do Do that on a WEb PAge?
>>
>><https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite>
>>
>
>All right, trying to get this.
>-- 

Still trying to see how to implement this in an .html page.

Meawhile when I turn on the CSP the calculator is surpressed

and from the chrome debug we get

Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' https://www.nk.ca https://secure.nl2k.ab.ca https://cdn.jsdelivr.net/ https://code.jquery.com https://ajax.googleapis.com https://cdnjs.cloudflare.com/ https://ssl.google-analytics.com https://assets.zendesk.com https://connect.facebook.net https://www3.moneris.com/ ". Either the 'unsafe-inline' keyword, a hash ('sha256-PIiPJXfBkkwdkWWFA7MWowVWRKJQkLqnr9eToZB+1Kk='), or a nonce ('nonce-...') is required to enable inline execution.


-- 
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b  
BC save the Province; on 24 October 2020, vote Liberal and not NDP!

[toc] | [prev] | [next] | [standalone]


#39033

From"Michael Haufe (TNO)" <tno@thenewobjective.com>
Date2020-10-22 11:46 -0700
Message-ID<7eb85e54-65c1-4541-a04f-a186e67f8a3dn@googlegroups.com>
In reply to#39030
On Thursday, October 22, 2020 at 8:41:54 AM UTC-5, The Doctor wrote:
> In article <rmpert$1qts$3...@gallifrey.nk.ca>,
> The Doctor <doc...@doctor.nl2k.ab.ca> wrote: 
> >In article <457449fa-50ef-4d27...@googlegroups.com>, 
> >Michael Haufe (TNO) <t...@thenewobjective.com> wrote: 
> >>On Tuesday, October 20, 2020 at 8:14:35 AM UTC-5, The Doctor wrote: 
> >> 
> >>> Indicate whether to send a cookie in a cross-site request by 
> >>specifying its SameSite attribute 
> >>> 
> >>> How do Do that on a WEb PAge? 
> >> 
> >><https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite> 
> >> 
> > 
> >All right, trying to get this. 
> >--
> Still trying to see how to implement this in an .html page. 

This one has to be done on the server.

If you're using Apache:

<https://stackoverflow.com/a/59128049/153209>

If you're using IIS:

<https://docs.microsoft.com/en-us/aspnet/samesite/system-web-samesite>

For Node.js (Express)

```
res.cookie(‘sessionID’, user.sessionID, { secure: true, sameSite: true }); 
```

> Meawhile when I turn on the CSP the calculator is surpressed 
> 
> and from the chrome debug we get 
> 
> Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' https://www.nk.ca https://secure.nl2k.ab.ca https://cdn.jsdelivr.net/ https://code.jquery.com https://ajax.googleapis.com https://cdnjs.cloudflare.com/ https://ssl.google-analytics.com https://assets.zendesk.com https://connect.facebook.net https://www3.moneris.com/ ". Either the 'unsafe-inline' keyword, a hash ('sha256-PIiPJXfBkkwdkWWFA7MWowVWRKJQkLqnr9eToZB+1Kk='), or a nonce ('nonce-...') is required to enable inline execution.

The key part here is: "Refused to execute inline script"

Your current policy demands that all JavaScript be included via a <script> tag. So move the inline scripts to external files

Otherwise you need to add 'unsafe-inline' to the script-src.

Note that if you use 'unsafe-inline' you're observatory score [1] will be lower.

[1] <https://observatory.mozilla.org/>

[toc] | [prev] | [next] | [standalone]


#39034

Fromdoctor@doctor.nl2k.ab.ca (The Doctor)
Date2020-10-22 22:36 +0000
Message-ID<rmt1hd$204j$80@gallifrey.nk.ca>
In reply to#39033
In article <7eb85e54-65c1-4541-a04f-a186e67f8a3dn@googlegroups.com>,
Michael Haufe (TNO) <tno@thenewobjective.com> wrote:
>On Thursday, October 22, 2020 at 8:41:54 AM UTC-5, The Doctor wrote:
>> In article <rmpert$1qts$3...@gallifrey.nk.ca>,
>> The Doctor <doc...@doctor.nl2k.ab.ca> wrote: 
>> >In article <457449fa-50ef-4d27...@googlegroups.com>, 
>> >Michael Haufe (TNO) <t...@thenewobjective.com> wrote: 
>> >>On Tuesday, October 20, 2020 at 8:14:35 AM UTC-5, The Doctor wrote: 
>> >> 
>> >>> Indicate whether to send a cookie in a cross-site request by 
>> >>specifying its SameSite attribute 
>> >>> 
>> >>> How do Do that on a WEb PAge? 
>> >> 
>>
>>><https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite> 
>> >> 
>> > 
>> >All right, trying to get this. 
>> >--
>> Still trying to see how to implement this in an .html page. 
>
>This one has to be done on the server.
>
>If you're using Apache:
>
><https://stackoverflow.com/a/59128049/153209>
>
>If you're using IIS:
>
><https://docs.microsoft.com/en-us/aspnet/samesite/system-web-samesite>
>
>For Node.js (Express)
>
>```
>res.cookie(‘sessionID’, user.sessionID, { secure: true, sameSite: true }); 
>```

Nginx so similar to apache.

>
>> Meawhile when I turn on the CSP the calculator is surpressed 
>> 
>> and from the chrome debug we get 
>> 
>> Refused to execute inline script because it violates the following
>Content Security Policy directive: "script-src 'self' https://www.nk.ca
>https://secure.nl2k.ab.ca https://cdn.jsdelivr.net/
>https://code.jquery.com https://ajax.googleapis.com
>https://cdnjs.cloudflare.com/ https://ssl.google-analytics.com
>https://assets.zendesk.com https://connect.facebook.net
>https://www3.moneris.com/ ". Either the 'unsafe-inline' keyword, a hash
>('sha256-PIiPJXfBkkwdkWWFA7MWowVWRKJQkLqnr9eToZB+1Kk='), or a nonce
>('nonce-...') is required to enable inline execution.
>
>The key part here is: "Refused to execute inline script"
>
>Your current policy demands that all JavaScript be included via a
><script> tag. So move the inline scripts to external files
>

More work it is.


>Otherwise you need to add 'unsafe-inline' to the script-src.
>
>Note that if you use 'unsafe-inline' you're observatory score [1] will be lower.

That is noted.

Mixed php and javascript can be a headache esp when 
you are calling a MYSQL ish database.

>
>[1] <https://observatory.mozilla.org/>


-- 
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b  
BC save the Province; on 24 October 2020, vote Liberal and not NDP!

[toc] | [prev] | [next] | [standalone]


#39036

Fromdoctor@doctor.nl2k.ab.ca (The Doctor)
Date2020-10-24 02:42 +0000
Message-ID<rn04ao$tvh$33@gallifrey.nk.ca>
In reply to#39034
In article <rmt1hd$204j$80@gallifrey.nk.ca>,
The Doctor <doctor@doctor.nl2k.ab.ca> wrote:
>In article <7eb85e54-65c1-4541-a04f-a186e67f8a3dn@googlegroups.com>,
>Michael Haufe (TNO) <tno@thenewobjective.com> wrote:
>>On Thursday, October 22, 2020 at 8:41:54 AM UTC-5, The Doctor wrote:
>>> In article <rmpert$1qts$3...@gallifrey.nk.ca>,
>>> The Doctor <doc...@doctor.nl2k.ab.ca> wrote: 
>>> >In article <457449fa-50ef-4d27...@googlegroups.com>, 
>>> >Michael Haufe (TNO) <t...@thenewobjective.com> wrote: 
>>> >>On Tuesday, October 20, 2020 at 8:14:35 AM UTC-5, The Doctor wrote: 
>>> >> 
>>> >>> Indicate whether to send a cookie in a cross-site request by 
>>> >>specifying its SameSite attribute 
>>> >>> 
>>> >>> How do Do that on a WEb PAge? 
>>> >> 
>>>
>>>><https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite> 
>>> >> 
>>> > 
>>> >All right, trying to get this. 
>>> >--
>>> Still trying to see how to implement this in an .html page. 
>>
>>This one has to be done on the server.
>>
>>If you're using Apache:
>>
>><https://stackoverflow.com/a/59128049/153209>
>>
>>If you're using IIS:
>>
>><https://docs.microsoft.com/en-us/aspnet/samesite/system-web-samesite>
>>
>>For Node.js (Express)
>>
>>```
>>res.cookie(‘sessionID’, user.sessionID, { secure: true, sameSite: true }); 
>>```
>
>Nginx so similar to apache.
>
>>
>>> Meawhile when I turn on the CSP the calculator is surpressed 
>>> 
>>> and from the chrome debug we get 
>>> 
>>> Refused to execute inline script because it violates the following
>>Content Security Policy directive: "script-src 'self' https://www.nk.ca
>>https://secure.nl2k.ab.ca https://cdn.jsdelivr.net/
>>https://code.jquery.com https://ajax.googleapis.com
>>https://cdnjs.cloudflare.com/ https://ssl.google-analytics.com
>>https://assets.zendesk.com https://connect.facebook.net
>>https://www3.moneris.com/ ". Either the 'unsafe-inline' keyword, a hash
>>('sha256-PIiPJXfBkkwdkWWFA7MWowVWRKJQkLqnr9eToZB+1Kk='), or a nonce
>>('nonce-...') is required to enable inline execution.
>>
>>The key part here is: "Refused to execute inline script"
>>
>>Your current policy demands that all JavaScript be included via a
>><script> tag. So move the inline scripts to external files
>>
>
>More work it is.
>
>
>>Otherwise you need to add 'unsafe-inline' to the script-src.
>>
>>Note that if you use 'unsafe-inline' you're observatory score [1] will
>be lower.
>
>That is noted.
>
>Mixed php and javascript can be a headache esp when 
>you are calling a MYSQL ish database.
>

And since vital php calls a re main from inside the javascript,
there is no way to externise the scripts.

>>
>>[1] <https://observatory.mozilla.org/>
>
>
>-- 
>Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
>Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
>Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b  
>BC save the Province; on 24 October 2020, vote Liberal and not NDP!


-- 
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b  
BC save the Province; on 24 October 2020, vote Liberal and not NDP!

[toc] | [prev] | [next] | [standalone]


#39037

From"Michael Haufe (TNO)" <tno@thenewobjective.com>
Date2020-10-24 14:47 -0700
Message-ID<e346df7b-2f82-42d3-8adc-8f3e32b69c41n@googlegroups.com>
In reply to#39036
On Friday, October 23, 2020 at 9:42:42 PM UTC-5, The Doctor wrote:
> In article <rmt1hd$204j$8...@gallifrey.nk.ca>,
> The Doctor <doc...@doctor.nl2k.ab.ca> wrote: 

> >Mixed php and javascript can be a headache esp when 
> >you are calling a MYSQL ish database. 
> >
> And since vital php calls a re main from inside the javascript, 
> there is no way to externise the scripts.

It's not impossible nor necessarily a difficult thing to accomplish.

If you have an example script you need to externalize I'm sure we could offer 
suggestions.

Basically what I would do is have PHP output its variables into one or
more <input type="hidden" value="<% ... %>"> fields.

Then have the JavaScript code reference those fields.

[toc] | [prev] | [next] | [standalone]


#39038

From"Evertjan." <exxjxw.hannivoort@inter.nl.net>
Date2020-10-25 00:05 +0200
Message-ID<XnsAC61101EBF9eejj99@194.109.6.166>
In reply to#39037
"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 24 Oct 2020 in
comp.lang.javascript: 

> On Friday, October 23, 2020 at 9:42:42 PM UTC-5, The Doctor wrote:
>> In article <rmt1hd$204j$8...@gallifrey.nk.ca>,
>> The Doctor <doc...@doctor.nl2k.ab.ca> wrote: 
> 
>> >Mixed php and javascript can be a headache esp when 
>> >you are calling a MYSQL ish database. 
>> >
>> And since vital php calls a re main from inside the javascript, 
>> there is no way to externise the scripts.
> 
> It's not impossible nor necessarily a difficult thing to accomplish.
> 
> If you have an example script you need to externalize I'm sure we could
> offer suggestions.
> 
> Basically what I would do is have PHP output its variables into one or
> more <input type="hidden" value="<% ... %>"> fields.
> 
> Then have the JavaScript code reference those fields.

No need for that, you can just use serverside php 
put litterals into a clientside javascript variable:

<?php
   phpStringVar = 'Hello world.';
?>
<script>
  let jsStringVar = '<? = phpStringVar; ?>';
</script>


see:
<https://www.php.net/manual/en/getting-started.php>


-- 
Evertjan.
The Netherlands.
(Please change the x'es to dots in my emailaddress)

[toc] | [prev] | [next] | [standalone]


#39039

From"Michael Haufe (TNO)" <tno@thenewobjective.com>
Date2020-10-24 15:24 -0700
Message-ID<16e67386-e0d3-49c2-b6a2-86d0992178a0n@googlegroups.com>
In reply to#39038
On Saturday, October 24, 2020 at 5:06:07 PM UTC-5, Evertjan. wrote:
> "Michael Haufe (TNO)" <t...@thenewobjective.com> wrote on 24 Oct 2020 in 
> comp.lang.javascript:

[...]

> > Basically what I would do is have PHP output its variables into one or 
> > more <input type="hidden" value="<% ... %>"> fields. 
> > 
> > Then have the JavaScript code reference those fields.
> No need for that, you can just use serverside php 
> put litterals into a clientside javascript variable: 
> 
> <?php 
> phpStringVar = 'Hello world.'; 
> ?> 
> <script> 
> let jsStringVar = '<? = phpStringVar; ?>'; 
> </script> 
>
[...]

This would still violate the Content Security Policy though. No inline scripts allowed.

Additionally I don't think the server will process *.js files by default so 
`let jsStringVar = '<? = phpStringVar; ?>'; ` wouldn't do anything.

To make that work while obeying the CSP you'd have to do something like this in your .htaccess file:

```
AddType application/x-httpd-php .js

AddHandler x-httpd-php5 .js

<FilesMatch "\.(js|php)$">
SetHandler application/x-httpd-php
</FilesMatch>
```

But I think that's a bad idea since your PHP files could be exposed to the client.

I'm admittedly out of date on PHP/apache  configuration so if there is a better way I'd be curious
to see the alternatives

[toc] | [prev] | [next] | [standalone]


#39040

From"Evertjan." <exxjxw.hannivoort@inter.nl.net>
Date2020-10-25 00:53 +0200
Message-ID<XnsAC61906C5C30eejj99@194.109.6.166>
In reply to#39039
"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in
comp.lang.javascript: 

>> <?php 
>> phpStringVar = 'Hello world.'; 
>> ?> 
>> <script> 
>> let jsStringVar = '<? = phpStringVar; ?>'; 
>> </script> 
>>
> [...]
> 
> This would still violate the Content Security Policy though.

Serverside there is no cross-origin restriction. the server can read 
anything it can find on the web by for instance using:

<?php
   fopen("http://google.com/", "r"); 
?>

<https://www.php.net/manual/en/function.fopen.php>

==================================

> No inline scripts allowed. 

The php scripts won't reach clientside, they are used in the serverside php-
engine and scrubbed from the html/css/javascript-stream. 

> Additionally I don't think the server will process *.js files by default

You mean php-engine processing, I presume.

Start with experimenting with putting all script in your .php file.

later you can make seperate js files,
which should either be extended as .php,

<script src = '/js/myJsFile.php' ></script>

Later you can perhaps accomodate the server to also preprocess js files].
However the separate js-files could be cached by the browser, so either 
prevent that, or use javscript in your main file.




> so `let jsStringVar = '<? = phpStringVar; ?>'; ` wouldn't do anything.
> 
> To make that work while obeying the CSP you'd have to do something like
> this in your .htaccess file: 
> 
> ```
> AddType application/x-httpd-php .js
> 
> AddHandler x-httpd-php5 .js
> 
> <FilesMatch "\.(js|php)$">
> SetHandler application/x-httpd-php
> </FilesMatch>
> ```
> 



-- 
Evertjan.
The Netherlands.
(Please change the x'es to dots in my emailaddress)

[toc] | [prev] | [next] | [standalone]


#39041

Fromdoctor@doctor.nl2k.ab.ca (The Doctor)
Date2020-10-24 23:42 +0000
Message-ID<rn2e4n$1529$11@gallifrey.nk.ca>
In reply to#39040
In article <XnsAC61906C5C30eejj99@194.109.6.166>,
Evertjan. <exxjxw.hannivoort@inter.nl.net> wrote:
>"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in
>comp.lang.javascript: 
>
>>> <?php 
>>> phpStringVar = 'Hello world.'; 
>>> ?> 
>>> <script> 
>>> let jsStringVar = '<? = phpStringVar; ?>'; 
>>> </script> 
>>>
>> [...]
>> 
>> This would still violate the Content Security Policy though.
>
>Serverside there is no cross-origin restriction. the server can read 
>anything it can find on the web by for instance using:
>
><?php
>   fopen("http://google.com/", "r"); 
>?>
>
><https://www.php.net/manual/en/function.fopen.php>
>
>==================================
>
>> No inline scripts allowed. 
>
>The php scripts won't reach clientside, they are used in the serverside php-
>engine and scrubbed from the html/css/javascript-stream. 
>
>> Additionally I don't think the server will process *.js files by default
>
>You mean php-engine processing, I presume.
>
>Start with experimenting with putting all script in your .php file.
>
>later you can make seperate js files,
>which should either be extended as .php,
>
><script src = '/js/myJsFile.php' ></script>
>
>Later you can perhaps accomodate the server to also preprocess js files].
>However the separate js-files could be cached by the browser, so either 
>prevent that, or use javscript in your main file.
>
>
>
>
>> so `let jsStringVar = '<? = phpStringVar; ?>'; ` wouldn't do anything.
>> 
>> To make that work while obeying the CSP you'd have to do something like
>> this in your .htaccess file: 
>> 
>> ```
>> AddType application/x-httpd-php .js
>> 
>> AddHandler x-httpd-php5 .js
>> 
>> <FilesMatch "\.(js|php)$">
>> SetHandler application/x-httpd-php
>> </FilesMatch>
>> ```
>> 
>
>
>
>-- 
>Evertjan.
>The Netherlands.
>(Please change the x'es to dots in my emailaddress)

Suggestions to explore.
-- 
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b  
Sask save the Province; on 26 October 2020, vote Liberal and not NDP nor SKP!

[toc] | [prev] | [next] | [standalone]


#39042

From"Michael Haufe (TNO)" <tno@thenewobjective.com>
Date2020-10-24 21:19 -0700
Message-ID<a5e688ff-7dac-4821-9009-e3ef1ec49056n@googlegroups.com>
In reply to#39040
On Saturday, October 24, 2020 at 6:00:10 PM UTC-5, Evertjan. wrote:
> "Michael Haufe (TNO)" <t...@thenewobjective.com> wrote on 25 Oct 2020 in 
> comp.lang.javascript:
> >> <?php 
> >> phpStringVar = 'Hello world.'; 
> >> ?> 
> >> <script> 
> >> let jsStringVar = '<? = phpStringVar; ?>'; 
> >> </script> 
> >> 
> > [...] 
> > 
> > This would still violate the Content Security Policy though.
> Serverside there is no cross-origin restriction. the server can read 
> anything it can find on the web by for instance using: 
> 
> <?php 
> fopen("http://google.com/", "r"); 
> ?> 
> 
> <https://www.php.net/manual/en/function.fopen.php> 

The goal is to honor the CSP though for the client, so you seem to be making an orthogonal point. I don't see the relevance.

> > No inline scripts allowed. 
> 
> The php scripts won't reach clientside, they are used in the serverside php- 
> engine and scrubbed from the html/css/javascript-stream.

Which would require *.js being processed by PHP which it doesn't by default AFAIK

> > Additionally I don't think the server will process *.js files by default
> You mean php-engine processing, I presume. 
> 
> Start with experimenting with putting all script in your .php file. 
> 
> later you can make seperate js files, 
> which should either be extended as .php, 
> 
> <script src = '/js/myJsFile.php' ></script> 

Yes, this is possible but you'd have to manually set the header. Also this seems unintuitive.
Personally I'd prefer a separation of concerns and not mix and match languages like this.
Deferring to The Doctor of course...

[toc] | [prev] | [next] | [standalone]


#39043

From"Evertjan." <exxjxw.hannivoort@inter.nl.net>
Date2020-10-25 15:33 +0100
Message-ID<XnsAC619E3241BE1eejj99@194.109.6.166>
In reply to#39042
"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in
comp.lang.javascript: 

>> <script src = '/js/myJsFile.php' ></script> 
> 
> Yes, this is possible but you'd have to manually set the header. Also
> this seems unintuitive. Personally I'd prefer a separation of concerns
> and not mix and match languages like this. Deferring to The Doctor of
> course... 

I do this quite often, [with classic ASP].

The languages are not mixed, the js-file is just preprocessed.

The main problem is the caching in the client, 
so I will do the dynamic part as inmainsteam javascript, not as js-file. 

-- 
Evertjan.
The Netherlands.
(Please change the x'es to dots in my emailaddress)

[toc] | [prev] | [next] | [standalone]


#39044

Fromdoctor@doctor.nl2k.ab.ca (The Doctor)
Date2020-10-25 18:49 +0000
Message-ID<rn4hb8$1b05$24@gallifrey.nk.ca>
In reply to#39043
In article <XnsAC619E3241BE1eejj99@194.109.6.166>,
Evertjan. <exxjxw.hannivoort@inter.nl.net> wrote:
>"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in
>comp.lang.javascript: 
>
>>> <script src = '/js/myJsFile.php' ></script> 
>> 
>> Yes, this is possible but you'd have to manually set the header. Also
>> this seems unintuitive. Personally I'd prefer a separation of concerns
>> and not mix and match languages like this. Deferring to The Doctor of
>> course... 
>
>I do this quite often, [with classic ASP].
>
>The languages are not mixed, the js-file is just preprocessed.
>
>The main problem is the caching in the client, 
>so I will do the dynamic part as inmainsteam javascript, not as js-file. 
>
>-- 
>Evertjan.
>The Netherlands.
>(Please change the x'es to dots in my emailaddress)

Can anyone find the original question?
-- 
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b  
Sask save the Province; on 26 October 2020, vote Liberal and not NDP nor SKP!

[toc] | [prev] | [next] | [standalone]


#39045

From"Michael Haufe (TNO)" <tno@thenewobjective.com>
Date2020-10-25 12:04 -0700
Message-ID<e7939fa1-fa19-4bfb-8fef-04f1f864a306n@googlegroups.com>
In reply to#39044
On Sunday, October 25, 2020 at 1:49:22 PM UTC-5, The Doctor wrote:

> Can anyone find the original question?

You said:

"""
And since vital php calls a re main from inside the javascript,
there is no way to externise the scripts.
"""

We disagree and have some approaches to accomplish this

[toc] | [prev] | [next] | [standalone]


#39046

From"Evertjan." <exxjxw.hannivoort@inter.nl.net>
Date2020-10-26 00:31 +0100
Message-ID<XnsAC6255C194A8eejj99@194.109.6.166>
In reply to#39045
"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in 
comp.lang.javascript:

> On Sunday, October 25, 2020 at 1:49:22 PM UTC-5, The Doctor wrote:
> 
>> Can anyone find the original question?
> 
> You said:
> 
> """
> And since vital php calls a re main from inside the javascript,
> there is no way to externise the scripts.
> """
> 
> We disagree and have some approaches to accomplish this

It started like this:

doctor@doctor.nl2k.ab.ca (The Doctor) wrote on 17 Oct 2020 in
comp.lang.javascript: 
> Anyone familiar with
> 
> https://developers.google.com/web/updates/2020/07/referrer-policy-new-chr
> ome-default/ 
> ?
> I have a php seesion that uses this javascript

 



-- 
Evertjan.
The Netherlands.
(Please change the x'es to dots in my emailaddress)

[toc] | [prev] | [next] | [standalone]


#39047

Fromdoctor@doctor.nl2k.ab.ca (The Doctor)
Date2020-10-26 00:44 +0000
Message-ID<rn5659$1no6$37@gallifrey.nk.ca>
In reply to#39045
In article <e7939fa1-fa19-4bfb-8fef-04f1f864a306n@googlegroups.com>,
Michael Haufe (TNO) <tno@thenewobjective.com> wrote:
>On Sunday, October 25, 2020 at 1:49:22 PM UTC-5, The Doctor wrote:
>
>> Can anyone find the original question?
>
>You said:
>
>"""
>And since vital php calls a re main from inside the javascript,
>there is no way to externise the scripts.
>"""
>
>We disagree and have some approaches to accomplish this

That is not the original post.
-- 
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b  
Sask save the Province; on 26 October 2020, vote Liberal and not NDP nor SKP!

[toc] | [prev] | [next] | [standalone]


#39016

From"Michael Haufe (TNO)" <tno@thenewobjective.com>
Date2020-10-20 09:47 -0700
Message-ID<2edf6a66-20d1-451e-9cba-c870b0689e50n@googlegroups.com>
In reply to#39011
On Tuesday, October 20, 2020 at 12:05:05 AM UTC-5, The Doctor wrote:
> In article <4a9258de-1151-49c0...@googlegroups.com>,
> Michael Haufe (TNO) <t...@thenewobjective.com> wrote:
> >On Monday, October 19, 2020 at 4:58:51 PM UTC-5, The Doctor wrote: 
> > 
> >> Referrer-Policy is working but the Content-Security-Policy shut down the 
> >> calculator and the CAPTCHA codes, both are based on javascript. 
> > 
> >Which means you're missing entries in your domain list. Just look at the 
> >error console and it will tell you which ones are missing.
> USing chrome I take it.

I'm using Brave, but it doesn't matter as any modern browser should give you the message.

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | comp.lang.javascript


csiph-web