diff --git a/apps/machine/electron/main.ts b/apps/machine/electron/main.ts index e3085d3..51f8bbe 100644 --- a/apps/machine/electron/main.ts +++ b/apps/machine/electron/main.ts @@ -6,7 +6,7 @@ * HAL hardware drivers run here (Node.js environment). */ -import { app, BrowserWindow, ipcMain } from 'electron' +import { app, BrowserWindow, ipcMain, session } from 'electron' import path from 'node:path' import fs from 'node:fs' import { fileURLToPath } from 'node:url' @@ -280,6 +280,18 @@ ipcMain.handle('hal:cleanup', async () => { // App lifecycle app.whenReady().then(() => { + // Enforce Content Security Policy via HTTP headers (defense-in-depth alongside meta tag) + session.defaultSession.webRequest.onHeadersReceived((details, callback) => { + callback({ + responseHeaders: { + ...details.responseHeaders, + 'Content-Security-Policy': [ + "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self' ws: wss: http: https:; img-src 'self' data: blob:; font-src 'self'; frame-src 'none'; object-src 'none'", + ], + }, + }) + }) + initDatabase() // Seed cassettes from env/preset if DB table is empty. diff --git a/apps/machine/index.html b/apps/machine/index.html index b1d2992..cc57859 100644 --- a/apps/machine/index.html +++ b/apps/machine/index.html @@ -4,6 +4,20 @@ + +