Fez compiles templates and component scripts to JavaScript at runtime. That design has security consequences worth stating explicitly.
Fez treats .fez component sources, template strings, and handler attributes as
trusted application code. They are compiled with new Function and evaluated
in the page. This is the same trust model as loading a JavaScript file, and it is
why Fez needs a Content-Security-Policy that allows unsafe-eval.
Do not feed untrusted strings into any of the following. They are code-execution sinks by design:
Fez.compile(name, source)and<template fez>/<xmp fez>sourcescreateTemplate(text)andFez.createTemplate(text)fez.*/ bare calls insideon<event>attributes:attr="expr",fez-bind,fez-use, anddata-props/data-json-templateFez.getFunction(string)andFez.head({ script })- Inline
<script>tags returned by a pjax response
Everything that can be influenced by an end user or a remote server is treated as untrusted:
- Values interpolated with
{expr}are HTML-escaped. {@html expr}is raw by contract; only use it with sanitized content.Fez.nodeMorph/morphdomparse HTML from strings. A pjax response is same-origin only; never morph HTML from an origin you do not control.Fez.index.applyandFez.domRootwrite HTML withinnerHTML; pass only trusted demo/documentation markup.
Because component code is compiled and run at runtime, a strict CSP for a Fez app includes:
script-src 'self' 'unsafe-eval';
Applications that precompile all components and do not use inline handlers or
runtime Fez.compile can drop unsafe-eval.
Report suspected vulnerabilities via the repository issue tracker: https://github.com/dux/fez/issues