Loading portal/static/js/gitlab.mjs 0 → 100644 +43 −0 Original line number Diff line number Diff line /** * Functions to get data from gitlab.cl.uni-heidelberg.de (hosting the protocols repo) using the credentials * found in the browser session with gitlab.cl.uni-heidelberg.de. * * Wait, you might ask, shouldn't the Same Origin Policy * (https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy) prevent that? * — Yes, mostly. * * And this "mostly" is also the reason why this script is kinda a gigantic hack. * * For those who have never heard of the Same Origin Policy before: The general idea is that you * do not want a website (say "cute-cat-pics.totallylegit.example") make requests to another website * (e.g., "my-online-banking.example" or "private-messaging-service.example") in your name (i.e. * using the credentials found in the browser session for that page). Otherwise, the cute cat pics * website could steal all your personal messages and authorize money transfers from your account, * if you happen to be logged in. * * This was possible in the early days, found to be a massiv security hole, and patched. * However, because websites already started to depend on the mechanism for legitimate use cases, it * was decided against completely patching it (which could be achieved by having fully isolated containers * for credentials per website; a website would then be allowed to send requests to all other websites, * but never using credentials other than its own). * * This means it is possible to send requests to different websites, re-using their credentials, in certain * cases: https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy#cross-origin_network_access * Generally, you can send all the requests you want (re-using credentials!), but you cannot read the responses. * This would prevent the cute cat pics website from reading all your personal messages, but it could still * send money to other bank accounts. This is the reason why CSRF tokens were invented (basically, the bank * will only send money to another account when your browser can echo back a random string the bank sent it, * which the cute cat pics website could not read). * * Well, one exeception where you can send requests (re-using credentials) and read the responses is when embdeding * images. This means we use an image hosted at gitlab.cl.uni-heidelberg.de and only accessible to logged-in users * to determine if the user is logged in. */ async function canAccess(imageUrl) {} export async function isLoggedIn() {} export async function canAccessProtocols() {} export async function getLatestProtocolFileName() {} Loading
portal/static/js/gitlab.mjs 0 → 100644 +43 −0 Original line number Diff line number Diff line /** * Functions to get data from gitlab.cl.uni-heidelberg.de (hosting the protocols repo) using the credentials * found in the browser session with gitlab.cl.uni-heidelberg.de. * * Wait, you might ask, shouldn't the Same Origin Policy * (https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy) prevent that? * — Yes, mostly. * * And this "mostly" is also the reason why this script is kinda a gigantic hack. * * For those who have never heard of the Same Origin Policy before: The general idea is that you * do not want a website (say "cute-cat-pics.totallylegit.example") make requests to another website * (e.g., "my-online-banking.example" or "private-messaging-service.example") in your name (i.e. * using the credentials found in the browser session for that page). Otherwise, the cute cat pics * website could steal all your personal messages and authorize money transfers from your account, * if you happen to be logged in. * * This was possible in the early days, found to be a massiv security hole, and patched. * However, because websites already started to depend on the mechanism for legitimate use cases, it * was decided against completely patching it (which could be achieved by having fully isolated containers * for credentials per website; a website would then be allowed to send requests to all other websites, * but never using credentials other than its own). * * This means it is possible to send requests to different websites, re-using their credentials, in certain * cases: https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy#cross-origin_network_access * Generally, you can send all the requests you want (re-using credentials!), but you cannot read the responses. * This would prevent the cute cat pics website from reading all your personal messages, but it could still * send money to other bank accounts. This is the reason why CSRF tokens were invented (basically, the bank * will only send money to another account when your browser can echo back a random string the bank sent it, * which the cute cat pics website could not read). * * Well, one exeception where you can send requests (re-using credentials) and read the responses is when embdeding * images. This means we use an image hosted at gitlab.cl.uni-heidelberg.de and only accessible to logged-in users * to determine if the user is logged in. */ async function canAccess(imageUrl) {} export async function isLoggedIn() {} export async function canAccessProtocols() {} export async function getLatestProtocolFileName() {}