Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.javascript > #38966 > unrolled thread
| Started by | doctor@doctor.nl2k.ab.ca (The Doctor) |
|---|---|
| First post | 2020-10-17 02:59 +0000 |
| Last post | 2020-10-20 09:47 -0700 |
| Articles | 16 on this page of 36 — 4 participants |
Back to article view | Back to comp.lang.javascript
Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-17 02:59 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-16 21:45 -0700
Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-17 11:00 +0200
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-17 13:24 +0000
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-17 22:27 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-17 17:30 -0700
Re: Chrome and passing on cross-origin "J.O. Aho" <user@example.net> - 2020-10-18 16:14 +0200
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-18 10:17 -0700
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-18 22:15 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-18 15:31 -0700
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-19 00:54 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-18 18:51 -0700
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-19 02:43 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-18 19:48 -0700
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-19 21:58 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-19 21:11 -0700
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-20 05:04 +0000
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-20 13:14 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-20 09:47 -0700
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-21 13:59 +0000
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-22 13:41 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-22 11:46 -0700
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-22 22:36 +0000
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-24 02:42 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-24 14:47 -0700
Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-25 00:05 +0200
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-24 15:24 -0700
Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-25 00:53 +0200
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-24 23:42 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-24 21:19 -0700
Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-25 15:33 +0100
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-25 18:49 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-25 12:04 -0700
Re: Chrome and passing on cross-origin "Evertjan." <exxjxw.hannivoort@inter.nl.net> - 2020-10-26 00:31 +0100
Re: Chrome and passing on cross-origin doctor@doctor.nl2k.ab.ca (The Doctor) - 2020-10-26 00:44 +0000
Re: Chrome and passing on cross-origin "Michael Haufe (TNO)" <tno@thenewobjective.com> - 2020-10-20 09:47 -0700
Page 2 of 2 — ← Prev page 1 [2]
| From | doctor@doctor.nl2k.ab.ca (The Doctor) |
|---|---|
| Date | 2020-10-22 13:41 +0000 |
| Message-ID | <rms26o$1fch$1@gallifrey.nk.ca> |
| In reply to | #39022 |
In article <rmpert$1qts$3@gallifrey.nk.ca>,
The Doctor <doctor@doctor.nl2k.ab.ca> wrote:
>In article <457449fa-50ef-4d27-994c-14751ed6ebf9n@googlegroups.com>,
>Michael Haufe (TNO) <tno@thenewobjective.com> wrote:
>>On Tuesday, October 20, 2020 at 8:14:35 AM UTC-5, The Doctor wrote:
>>
>>> Indicate whether to send a cookie in a cross-site request by
>>specifying its SameSite attribute
>>>
>>> How do Do that on a WEb PAge?
>>
>><https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite>
>>
>
>All right, trying to get this.
>--
Still trying to see how to implement this in an .html page.
Meawhile when I turn on the CSP the calculator is surpressed
and from the chrome debug we get
Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' https://www.nk.ca https://secure.nl2k.ab.ca https://cdn.jsdelivr.net/ https://code.jquery.com https://ajax.googleapis.com https://cdnjs.cloudflare.com/ https://ssl.google-analytics.com https://assets.zendesk.com https://connect.facebook.net https://www3.moneris.com/ ". Either the 'unsafe-inline' keyword, a hash ('sha256-PIiPJXfBkkwdkWWFA7MWowVWRKJQkLqnr9eToZB+1Kk='), or a nonce ('nonce-...') is required to enable inline execution.
--
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
BC save the Province; on 24 October 2020, vote Liberal and not NDP!
[toc] | [prev] | [next] | [standalone]
| From | "Michael Haufe (TNO)" <tno@thenewobjective.com> |
|---|---|
| Date | 2020-10-22 11:46 -0700 |
| Message-ID | <7eb85e54-65c1-4541-a04f-a186e67f8a3dn@googlegroups.com> |
| In reply to | #39030 |
On Thursday, October 22, 2020 at 8:41:54 AM UTC-5, The Doctor wrote:
> In article <rmpert$1qts$3...@gallifrey.nk.ca>,
> The Doctor <doc...@doctor.nl2k.ab.ca> wrote:
> >In article <457449fa-50ef-4d27...@googlegroups.com>,
> >Michael Haufe (TNO) <t...@thenewobjective.com> wrote:
> >>On Tuesday, October 20, 2020 at 8:14:35 AM UTC-5, The Doctor wrote:
> >>
> >>> Indicate whether to send a cookie in a cross-site request by
> >>specifying its SameSite attribute
> >>>
> >>> How do Do that on a WEb PAge?
> >>
> >><https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite>
> >>
> >
> >All right, trying to get this.
> >--
> Still trying to see how to implement this in an .html page.
This one has to be done on the server.
If you're using Apache:
<https://stackoverflow.com/a/59128049/153209>
If you're using IIS:
<https://docs.microsoft.com/en-us/aspnet/samesite/system-web-samesite>
For Node.js (Express)
```
res.cookie(‘sessionID’, user.sessionID, { secure: true, sameSite: true });
```
> Meawhile when I turn on the CSP the calculator is surpressed
>
> and from the chrome debug we get
>
> Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' https://www.nk.ca https://secure.nl2k.ab.ca https://cdn.jsdelivr.net/ https://code.jquery.com https://ajax.googleapis.com https://cdnjs.cloudflare.com/ https://ssl.google-analytics.com https://assets.zendesk.com https://connect.facebook.net https://www3.moneris.com/ ". Either the 'unsafe-inline' keyword, a hash ('sha256-PIiPJXfBkkwdkWWFA7MWowVWRKJQkLqnr9eToZB+1Kk='), or a nonce ('nonce-...') is required to enable inline execution.
The key part here is: "Refused to execute inline script"
Your current policy demands that all JavaScript be included via a <script> tag. So move the inline scripts to external files
Otherwise you need to add 'unsafe-inline' to the script-src.
Note that if you use 'unsafe-inline' you're observatory score [1] will be lower.
[1] <https://observatory.mozilla.org/>
[toc] | [prev] | [next] | [standalone]
| From | doctor@doctor.nl2k.ab.ca (The Doctor) |
|---|---|
| Date | 2020-10-22 22:36 +0000 |
| Message-ID | <rmt1hd$204j$80@gallifrey.nk.ca> |
| In reply to | #39033 |
In article <7eb85e54-65c1-4541-a04f-a186e67f8a3dn@googlegroups.com>,
Michael Haufe (TNO) <tno@thenewobjective.com> wrote:
>On Thursday, October 22, 2020 at 8:41:54 AM UTC-5, The Doctor wrote:
>> In article <rmpert$1qts$3...@gallifrey.nk.ca>,
>> The Doctor <doc...@doctor.nl2k.ab.ca> wrote:
>> >In article <457449fa-50ef-4d27...@googlegroups.com>,
>> >Michael Haufe (TNO) <t...@thenewobjective.com> wrote:
>> >>On Tuesday, October 20, 2020 at 8:14:35 AM UTC-5, The Doctor wrote:
>> >>
>> >>> Indicate whether to send a cookie in a cross-site request by
>> >>specifying its SameSite attribute
>> >>>
>> >>> How do Do that on a WEb PAge?
>> >>
>>
>>><https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite>
>> >>
>> >
>> >All right, trying to get this.
>> >--
>> Still trying to see how to implement this in an .html page.
>
>This one has to be done on the server.
>
>If you're using Apache:
>
><https://stackoverflow.com/a/59128049/153209>
>
>If you're using IIS:
>
><https://docs.microsoft.com/en-us/aspnet/samesite/system-web-samesite>
>
>For Node.js (Express)
>
>```
>res.cookie(‘sessionID’, user.sessionID, { secure: true, sameSite: true });
>```
Nginx so similar to apache.
>
>> Meawhile when I turn on the CSP the calculator is surpressed
>>
>> and from the chrome debug we get
>>
>> Refused to execute inline script because it violates the following
>Content Security Policy directive: "script-src 'self' https://www.nk.ca
>https://secure.nl2k.ab.ca https://cdn.jsdelivr.net/
>https://code.jquery.com https://ajax.googleapis.com
>https://cdnjs.cloudflare.com/ https://ssl.google-analytics.com
>https://assets.zendesk.com https://connect.facebook.net
>https://www3.moneris.com/ ". Either the 'unsafe-inline' keyword, a hash
>('sha256-PIiPJXfBkkwdkWWFA7MWowVWRKJQkLqnr9eToZB+1Kk='), or a nonce
>('nonce-...') is required to enable inline execution.
>
>The key part here is: "Refused to execute inline script"
>
>Your current policy demands that all JavaScript be included via a
><script> tag. So move the inline scripts to external files
>
More work it is.
>Otherwise you need to add 'unsafe-inline' to the script-src.
>
>Note that if you use 'unsafe-inline' you're observatory score [1] will be lower.
That is noted.
Mixed php and javascript can be a headache esp when
you are calling a MYSQL ish database.
>
>[1] <https://observatory.mozilla.org/>
--
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
BC save the Province; on 24 October 2020, vote Liberal and not NDP!
[toc] | [prev] | [next] | [standalone]
| From | doctor@doctor.nl2k.ab.ca (The Doctor) |
|---|---|
| Date | 2020-10-24 02:42 +0000 |
| Message-ID | <rn04ao$tvh$33@gallifrey.nk.ca> |
| In reply to | #39034 |
In article <rmt1hd$204j$80@gallifrey.nk.ca>,
The Doctor <doctor@doctor.nl2k.ab.ca> wrote:
>In article <7eb85e54-65c1-4541-a04f-a186e67f8a3dn@googlegroups.com>,
>Michael Haufe (TNO) <tno@thenewobjective.com> wrote:
>>On Thursday, October 22, 2020 at 8:41:54 AM UTC-5, The Doctor wrote:
>>> In article <rmpert$1qts$3...@gallifrey.nk.ca>,
>>> The Doctor <doc...@doctor.nl2k.ab.ca> wrote:
>>> >In article <457449fa-50ef-4d27...@googlegroups.com>,
>>> >Michael Haufe (TNO) <t...@thenewobjective.com> wrote:
>>> >>On Tuesday, October 20, 2020 at 8:14:35 AM UTC-5, The Doctor wrote:
>>> >>
>>> >>> Indicate whether to send a cookie in a cross-site request by
>>> >>specifying its SameSite attribute
>>> >>>
>>> >>> How do Do that on a WEb PAge?
>>> >>
>>>
>>>><https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite>
>>> >>
>>> >
>>> >All right, trying to get this.
>>> >--
>>> Still trying to see how to implement this in an .html page.
>>
>>This one has to be done on the server.
>>
>>If you're using Apache:
>>
>><https://stackoverflow.com/a/59128049/153209>
>>
>>If you're using IIS:
>>
>><https://docs.microsoft.com/en-us/aspnet/samesite/system-web-samesite>
>>
>>For Node.js (Express)
>>
>>```
>>res.cookie(‘sessionID’, user.sessionID, { secure: true, sameSite: true });
>>```
>
>Nginx so similar to apache.
>
>>
>>> Meawhile when I turn on the CSP the calculator is surpressed
>>>
>>> and from the chrome debug we get
>>>
>>> Refused to execute inline script because it violates the following
>>Content Security Policy directive: "script-src 'self' https://www.nk.ca
>>https://secure.nl2k.ab.ca https://cdn.jsdelivr.net/
>>https://code.jquery.com https://ajax.googleapis.com
>>https://cdnjs.cloudflare.com/ https://ssl.google-analytics.com
>>https://assets.zendesk.com https://connect.facebook.net
>>https://www3.moneris.com/ ". Either the 'unsafe-inline' keyword, a hash
>>('sha256-PIiPJXfBkkwdkWWFA7MWowVWRKJQkLqnr9eToZB+1Kk='), or a nonce
>>('nonce-...') is required to enable inline execution.
>>
>>The key part here is: "Refused to execute inline script"
>>
>>Your current policy demands that all JavaScript be included via a
>><script> tag. So move the inline scripts to external files
>>
>
>More work it is.
>
>
>>Otherwise you need to add 'unsafe-inline' to the script-src.
>>
>>Note that if you use 'unsafe-inline' you're observatory score [1] will
>be lower.
>
>That is noted.
>
>Mixed php and javascript can be a headache esp when
>you are calling a MYSQL ish database.
>
And since vital php calls a re main from inside the javascript,
there is no way to externise the scripts.
>>
>>[1] <https://observatory.mozilla.org/>
>
>
>--
>Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
>Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
>Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
>BC save the Province; on 24 October 2020, vote Liberal and not NDP!
--
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
BC save the Province; on 24 October 2020, vote Liberal and not NDP!
[toc] | [prev] | [next] | [standalone]
| From | "Michael Haufe (TNO)" <tno@thenewobjective.com> |
|---|---|
| Date | 2020-10-24 14:47 -0700 |
| Message-ID | <e346df7b-2f82-42d3-8adc-8f3e32b69c41n@googlegroups.com> |
| In reply to | #39036 |
On Friday, October 23, 2020 at 9:42:42 PM UTC-5, The Doctor wrote: > In article <rmt1hd$204j$8...@gallifrey.nk.ca>, > The Doctor <doc...@doctor.nl2k.ab.ca> wrote: > >Mixed php and javascript can be a headache esp when > >you are calling a MYSQL ish database. > > > And since vital php calls a re main from inside the javascript, > there is no way to externise the scripts. It's not impossible nor necessarily a difficult thing to accomplish. If you have an example script you need to externalize I'm sure we could offer suggestions. Basically what I would do is have PHP output its variables into one or more <input type="hidden" value="<% ... %>"> fields. Then have the JavaScript code reference those fields.
[toc] | [prev] | [next] | [standalone]
| From | "Evertjan." <exxjxw.hannivoort@inter.nl.net> |
|---|---|
| Date | 2020-10-25 00:05 +0200 |
| Message-ID | <XnsAC61101EBF9eejj99@194.109.6.166> |
| In reply to | #39037 |
"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 24 Oct 2020 in comp.lang.javascript: > On Friday, October 23, 2020 at 9:42:42 PM UTC-5, The Doctor wrote: >> In article <rmt1hd$204j$8...@gallifrey.nk.ca>, >> The Doctor <doc...@doctor.nl2k.ab.ca> wrote: > >> >Mixed php and javascript can be a headache esp when >> >you are calling a MYSQL ish database. >> > >> And since vital php calls a re main from inside the javascript, >> there is no way to externise the scripts. > > It's not impossible nor necessarily a difficult thing to accomplish. > > If you have an example script you need to externalize I'm sure we could > offer suggestions. > > Basically what I would do is have PHP output its variables into one or > more <input type="hidden" value="<% ... %>"> fields. > > Then have the JavaScript code reference those fields. No need for that, you can just use serverside php put litterals into a clientside javascript variable: <?php phpStringVar = 'Hello world.'; ?> <script> let jsStringVar = '<? = phpStringVar; ?>'; </script> see: <https://www.php.net/manual/en/getting-started.php> -- Evertjan. The Netherlands. (Please change the x'es to dots in my emailaddress)
[toc] | [prev] | [next] | [standalone]
| From | "Michael Haufe (TNO)" <tno@thenewobjective.com> |
|---|---|
| Date | 2020-10-24 15:24 -0700 |
| Message-ID | <16e67386-e0d3-49c2-b6a2-86d0992178a0n@googlegroups.com> |
| In reply to | #39038 |
On Saturday, October 24, 2020 at 5:06:07 PM UTC-5, Evertjan. wrote: > "Michael Haufe (TNO)" <t...@thenewobjective.com> wrote on 24 Oct 2020 in > comp.lang.javascript: [...] > > Basically what I would do is have PHP output its variables into one or > > more <input type="hidden" value="<% ... %>"> fields. > > > > Then have the JavaScript code reference those fields. > No need for that, you can just use serverside php > put litterals into a clientside javascript variable: > > <?php > phpStringVar = 'Hello world.'; > ?> > <script> > let jsStringVar = '<? = phpStringVar; ?>'; > </script> > [...] This would still violate the Content Security Policy though. No inline scripts allowed. Additionally I don't think the server will process *.js files by default so `let jsStringVar = '<? = phpStringVar; ?>'; ` wouldn't do anything. To make that work while obeying the CSP you'd have to do something like this in your .htaccess file: ``` AddType application/x-httpd-php .js AddHandler x-httpd-php5 .js <FilesMatch "\.(js|php)$"> SetHandler application/x-httpd-php </FilesMatch> ``` But I think that's a bad idea since your PHP files could be exposed to the client. I'm admittedly out of date on PHP/apache configuration so if there is a better way I'd be curious to see the alternatives
[toc] | [prev] | [next] | [standalone]
| From | "Evertjan." <exxjxw.hannivoort@inter.nl.net> |
|---|---|
| Date | 2020-10-25 00:53 +0200 |
| Message-ID | <XnsAC61906C5C30eejj99@194.109.6.166> |
| In reply to | #39039 |
"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in
comp.lang.javascript:
>> <?php
>> phpStringVar = 'Hello world.';
>> ?>
>> <script>
>> let jsStringVar = '<? = phpStringVar; ?>';
>> </script>
>>
> [...]
>
> This would still violate the Content Security Policy though.
Serverside there is no cross-origin restriction. the server can read
anything it can find on the web by for instance using:
<?php
fopen("http://google.com/", "r");
?>
<https://www.php.net/manual/en/function.fopen.php>
==================================
> No inline scripts allowed.
The php scripts won't reach clientside, they are used in the serverside php-
engine and scrubbed from the html/css/javascript-stream.
> Additionally I don't think the server will process *.js files by default
You mean php-engine processing, I presume.
Start with experimenting with putting all script in your .php file.
later you can make seperate js files,
which should either be extended as .php,
<script src = '/js/myJsFile.php' ></script>
Later you can perhaps accomodate the server to also preprocess js files].
However the separate js-files could be cached by the browser, so either
prevent that, or use javscript in your main file.
> so `let jsStringVar = '<? = phpStringVar; ?>'; ` wouldn't do anything.
>
> To make that work while obeying the CSP you'd have to do something like
> this in your .htaccess file:
>
> ```
> AddType application/x-httpd-php .js
>
> AddHandler x-httpd-php5 .js
>
> <FilesMatch "\.(js|php)$">
> SetHandler application/x-httpd-php
> </FilesMatch>
> ```
>
--
Evertjan.
The Netherlands.
(Please change the x'es to dots in my emailaddress)
[toc] | [prev] | [next] | [standalone]
| From | doctor@doctor.nl2k.ab.ca (The Doctor) |
|---|---|
| Date | 2020-10-24 23:42 +0000 |
| Message-ID | <rn2e4n$1529$11@gallifrey.nk.ca> |
| In reply to | #39040 |
In article <XnsAC61906C5C30eejj99@194.109.6.166>,
Evertjan. <exxjxw.hannivoort@inter.nl.net> wrote:
>"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in
>comp.lang.javascript:
>
>>> <?php
>>> phpStringVar = 'Hello world.';
>>> ?>
>>> <script>
>>> let jsStringVar = '<? = phpStringVar; ?>';
>>> </script>
>>>
>> [...]
>>
>> This would still violate the Content Security Policy though.
>
>Serverside there is no cross-origin restriction. the server can read
>anything it can find on the web by for instance using:
>
><?php
> fopen("http://google.com/", "r");
>?>
>
><https://www.php.net/manual/en/function.fopen.php>
>
>==================================
>
>> No inline scripts allowed.
>
>The php scripts won't reach clientside, they are used in the serverside php-
>engine and scrubbed from the html/css/javascript-stream.
>
>> Additionally I don't think the server will process *.js files by default
>
>You mean php-engine processing, I presume.
>
>Start with experimenting with putting all script in your .php file.
>
>later you can make seperate js files,
>which should either be extended as .php,
>
><script src = '/js/myJsFile.php' ></script>
>
>Later you can perhaps accomodate the server to also preprocess js files].
>However the separate js-files could be cached by the browser, so either
>prevent that, or use javscript in your main file.
>
>
>
>
>> so `let jsStringVar = '<? = phpStringVar; ?>'; ` wouldn't do anything.
>>
>> To make that work while obeying the CSP you'd have to do something like
>> this in your .htaccess file:
>>
>> ```
>> AddType application/x-httpd-php .js
>>
>> AddHandler x-httpd-php5 .js
>>
>> <FilesMatch "\.(js|php)$">
>> SetHandler application/x-httpd-php
>> </FilesMatch>
>> ```
>>
>
>
>
>--
>Evertjan.
>The Netherlands.
>(Please change the x'es to dots in my emailaddress)
Suggestions to explore.
--
Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
Sask save the Province; on 26 October 2020, vote Liberal and not NDP nor SKP!
[toc] | [prev] | [next] | [standalone]
| From | "Michael Haufe (TNO)" <tno@thenewobjective.com> |
|---|---|
| Date | 2020-10-24 21:19 -0700 |
| Message-ID | <a5e688ff-7dac-4821-9009-e3ef1ec49056n@googlegroups.com> |
| In reply to | #39040 |
On Saturday, October 24, 2020 at 6:00:10 PM UTC-5, Evertjan. wrote:
> "Michael Haufe (TNO)" <t...@thenewobjective.com> wrote on 25 Oct 2020 in
> comp.lang.javascript:
> >> <?php
> >> phpStringVar = 'Hello world.';
> >> ?>
> >> <script>
> >> let jsStringVar = '<? = phpStringVar; ?>';
> >> </script>
> >>
> > [...]
> >
> > This would still violate the Content Security Policy though.
> Serverside there is no cross-origin restriction. the server can read
> anything it can find on the web by for instance using:
>
> <?php
> fopen("http://google.com/", "r");
> ?>
>
> <https://www.php.net/manual/en/function.fopen.php>
The goal is to honor the CSP though for the client, so you seem to be making an orthogonal point. I don't see the relevance.
> > No inline scripts allowed.
>
> The php scripts won't reach clientside, they are used in the serverside php-
> engine and scrubbed from the html/css/javascript-stream.
Which would require *.js being processed by PHP which it doesn't by default AFAIK
> > Additionally I don't think the server will process *.js files by default
> You mean php-engine processing, I presume.
>
> Start with experimenting with putting all script in your .php file.
>
> later you can make seperate js files,
> which should either be extended as .php,
>
> <script src = '/js/myJsFile.php' ></script>
Yes, this is possible but you'd have to manually set the header. Also this seems unintuitive.
Personally I'd prefer a separation of concerns and not mix and match languages like this.
Deferring to The Doctor of course...
[toc] | [prev] | [next] | [standalone]
| From | "Evertjan." <exxjxw.hannivoort@inter.nl.net> |
|---|---|
| Date | 2020-10-25 15:33 +0100 |
| Message-ID | <XnsAC619E3241BE1eejj99@194.109.6.166> |
| In reply to | #39042 |
"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in comp.lang.javascript: >> <script src = '/js/myJsFile.php' ></script> > > Yes, this is possible but you'd have to manually set the header. Also > this seems unintuitive. Personally I'd prefer a separation of concerns > and not mix and match languages like this. Deferring to The Doctor of > course... I do this quite often, [with classic ASP]. The languages are not mixed, the js-file is just preprocessed. The main problem is the caching in the client, so I will do the dynamic part as inmainsteam javascript, not as js-file. -- Evertjan. The Netherlands. (Please change the x'es to dots in my emailaddress)
[toc] | [prev] | [next] | [standalone]
| From | doctor@doctor.nl2k.ab.ca (The Doctor) |
|---|---|
| Date | 2020-10-25 18:49 +0000 |
| Message-ID | <rn4hb8$1b05$24@gallifrey.nk.ca> |
| In reply to | #39043 |
In article <XnsAC619E3241BE1eejj99@194.109.6.166>, Evertjan. <exxjxw.hannivoort@inter.nl.net> wrote: >"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in >comp.lang.javascript: > >>> <script src = '/js/myJsFile.php' ></script> >> >> Yes, this is possible but you'd have to manually set the header. Also >> this seems unintuitive. Personally I'd prefer a separation of concerns >> and not mix and match languages like this. Deferring to The Doctor of >> course... > >I do this quite often, [with classic ASP]. > >The languages are not mixed, the js-file is just preprocessed. > >The main problem is the caching in the client, >so I will do the dynamic part as inmainsteam javascript, not as js-file. > >-- >Evertjan. >The Netherlands. >(Please change the x'es to dots in my emailaddress) Can anyone find the original question? -- Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising! Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b Sask save the Province; on 26 October 2020, vote Liberal and not NDP nor SKP!
[toc] | [prev] | [next] | [standalone]
| From | "Michael Haufe (TNO)" <tno@thenewobjective.com> |
|---|---|
| Date | 2020-10-25 12:04 -0700 |
| Message-ID | <e7939fa1-fa19-4bfb-8fef-04f1f864a306n@googlegroups.com> |
| In reply to | #39044 |
On Sunday, October 25, 2020 at 1:49:22 PM UTC-5, The Doctor wrote: > Can anyone find the original question? You said: """ And since vital php calls a re main from inside the javascript, there is no way to externise the scripts. """ We disagree and have some approaches to accomplish this
[toc] | [prev] | [next] | [standalone]
| From | "Evertjan." <exxjxw.hannivoort@inter.nl.net> |
|---|---|
| Date | 2020-10-26 00:31 +0100 |
| Message-ID | <XnsAC6255C194A8eejj99@194.109.6.166> |
| In reply to | #39045 |
"Michael Haufe (TNO)" <tno@thenewobjective.com> wrote on 25 Oct 2020 in comp.lang.javascript: > On Sunday, October 25, 2020 at 1:49:22 PM UTC-5, The Doctor wrote: > >> Can anyone find the original question? > > You said: > > """ > And since vital php calls a re main from inside the javascript, > there is no way to externise the scripts. > """ > > We disagree and have some approaches to accomplish this It started like this: doctor@doctor.nl2k.ab.ca (The Doctor) wrote on 17 Oct 2020 in comp.lang.javascript: > Anyone familiar with > > https://developers.google.com/web/updates/2020/07/referrer-policy-new-chr > ome-default/ > ? > I have a php seesion that uses this javascript -- Evertjan. The Netherlands. (Please change the x'es to dots in my emailaddress)
[toc] | [prev] | [next] | [standalone]
| From | doctor@doctor.nl2k.ab.ca (The Doctor) |
|---|---|
| Date | 2020-10-26 00:44 +0000 |
| Message-ID | <rn5659$1no6$37@gallifrey.nk.ca> |
| In reply to | #39045 |
In article <e7939fa1-fa19-4bfb-8fef-04f1f864a306n@googlegroups.com>, Michael Haufe (TNO) <tno@thenewobjective.com> wrote: >On Sunday, October 25, 2020 at 1:49:22 PM UTC-5, The Doctor wrote: > >> Can anyone find the original question? > >You said: > >""" >And since vital php calls a re main from inside the javascript, >there is no way to externise the scripts. >""" > >We disagree and have some approaches to accomplish this That is not the original post. -- Member - Liberal International This is doctor@@nl2k.ab.ca Ici doctor@@nl2k.ab.ca Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising! Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b Sask save the Province; on 26 October 2020, vote Liberal and not NDP nor SKP!
[toc] | [prev] | [next] | [standalone]
| From | "Michael Haufe (TNO)" <tno@thenewobjective.com> |
|---|---|
| Date | 2020-10-20 09:47 -0700 |
| Message-ID | <2edf6a66-20d1-451e-9cba-c870b0689e50n@googlegroups.com> |
| In reply to | #39011 |
On Tuesday, October 20, 2020 at 12:05:05 AM UTC-5, The Doctor wrote: > In article <4a9258de-1151-49c0...@googlegroups.com>, > Michael Haufe (TNO) <t...@thenewobjective.com> wrote: > >On Monday, October 19, 2020 at 4:58:51 PM UTC-5, The Doctor wrote: > > > >> Referrer-Policy is working but the Content-Security-Policy shut down the > >> calculator and the CAPTCHA codes, both are based on javascript. > > > >Which means you're missing entries in your domain list. Just look at the > >error console and it will tell you which ones are missing. > USing chrome I take it. I'm using Brave, but it doesn't matter as any modern browser should give you the message.
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | comp.lang.javascript
csiph-web