【问题标题】:Detect broken lock icon (mixed secure/insecure content) from Javascript从 Javascript 中检测损坏的锁图标(混合安全/不安全内容)
【发布时间】:2011-05-06 23:33:57
【问题描述】:

我正在努力使网站在 HTTPS 下完全正常运行。作为其中的一部分,我想确保我们永远不会“打破锁定”。也就是说,我们永远不应该在 SSL 页面上加载非 SSL 内容,这可能会根据浏览器触发警告或其他指示。为了验证这种情况,我想做两件事:

  1. 编写 Selenium 测试以验证各种操作不会破坏锁定。
  2. 在 JS 中编写日志代码,在用户会话期间检查锁是否被破坏,如果是,则记录回服务器。

有没有什么方法可以在JS中检查浏览器的HTTPS锁图标坏/未坏状态?或者等价的,当前页面内容的混合/非混合状态?

【问题讨论】:

    标签: javascript security ssl https selenium


    【解决方案1】:

    您可以遍历整个 DOM 并检查所有链接以确保它们是 https://

    【讨论】:

    • 这是个好主意,但没有考虑 XHR、JSONP 和帧间 RPC 请求。这是一个庞大的代码库,在错误出现之前很难发现它们,因此需要不断测试和记录。
    【解决方案2】:

    您无法从 JavaScript 本身检测到这一点,但您可以使用 Content-Security-Policy (CSP) HTTP 标头指示浏览器将混合内容的报告发送到您的服务器或第三方聚合服务。

    以下是向第三方服务 report-uri.io 报告混合内容的 CSP 标头示例:

    Content-Security-Policy-Report-Only: default-src https:; report-uri https://report-uri.io/report/<YOUR_NAME_HERE>

    This article Report URI 的维护者更详细地介绍了它的工作原理。如果愿意,您还可以将 CSP 标头配置为向您自己的 URL 报告。

    【讨论】:

      【解决方案3】:

      您可以使用Mixed Content Scan,这是我编写的一个 PHP CLI 脚本,用于扫描您的站点以查找混合内容。

      从 CLI 运行此脚本,例如:

      $ mixed-content-scan https://www.bram.us/
      

      脚本本身将在运行时开始扫描并提供反馈。当找到混合内容时,导致混合内容警告的 URL 将显示在屏幕上:

      $ mixed-content-scan https://www.bram.us/
      [2015-01-07 12:54:20] MCS.NOTICE: Scanning https://www.bram.us/ [] []
      [2015-01-07 12:54:21] MCS.INFO: 00000 - https://www.bram.us/ [] []
      [2015-01-07 12:54:22] MCS.INFO: 00001 - https://www.bram.us/projects/ [] []
      [2015-01-07 12:54:22] MCS.INFO: 00002 - https://www.bram.us/projects/mint-custom-title/ [] []
      [2015-01-07 12:54:23] MCS.INFO: 00003 - https://www.bram.us/projects/bramusicq/ [] []
      [2015-01-07 12:54:24] MCS.INFO: 00004 - https://www.bram.us/projects/gm_bramus/ [] []
      [2015-01-07 12:54:24] MCS.INFO: 00005 - https://www.bram.us/projects/js_bramus/ [] []
      [2015-01-07 12:54:26] MCS.INFO: 00006 - https://www.bram.us/projects/js_bramus/jsprogressbarhandler/ [] []
      [2015-01-07 12:54:27] MCS.INFO: 00007 - https://www.bram.us/projects/js_bramus/lazierload/ [] []
      [2015-01-07 12:54:27] MCS.INFO: 00008 - https://www.bram.us/projects/the-box-office/ [] []
      [2015-01-07 12:54:28] MCS.INFO: 00009 - https://www.bram.us/projects/tinymce-plugins/ [] []
      [2015-01-07 12:54:29] MCS.INFO: 00010 - https://www.bram.us/projects/tinymce-plugins/tinymce-classes-and-ids-plugin-bramus_cssextras/ [] []
      [2015-01-07 12:54:30] MCS.INFO: 00011 - https://www.bram.us/projects/flashlightboxinjector/ [] []
      
      ...
      
      [2015-01-07 12:54:45] MCS.INFO: 00036 - https://www.bram.us/2007/06/04/accessible-expanding-and-collapsing-menu/ [] []
      [2015-01-07 12:54:45] MCS.ERROR: 00037 - https://www.bram.us/demo/projects/jsprogressbarhandler/ [] []
      [2015-01-07 12:54:45] MCS.WARNING: http://www.google-analytics.com/urchin.js [] []
      [2015-01-07 12:54:46] MCS.INFO: 00038 - https://www.bram.us/2008/07/11/ror-progress-bar-helper/ [] []
      [2015-01-07 12:54:46] MCS.INFO: 00039 - https://www.bram.us/2008/11/10/jsprogressbarhandler-033/ [] []
      [2015-01-07 12:54:47] MCS.ERROR: 00040 - https://www.bram.us/demo/projects/lazierload/ [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1212/1285026452_0aeb38b6e6.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1074/1273115418_a77357040a.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1096/1273106588_91f7a736c6.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1324/1216309045_31ca82f9d9.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1262/1217169586_e4b2bfa7df.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1149/1216304291_63fd48d9c4.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1366/1216301505_51b3c590ff.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1184/1216299847_c57975bed2.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1085/1217158084_a9b059d25b.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1040/1216293529_3b7c044815.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1029/1084232736_5b8c023f46.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1318/1043062251_17071a8cc7.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://farm2.static.flickr.com/1221/1043059543_05713e6156.jpg [] []
      [2015-01-07 12:54:47] MCS.WARNING: http://www.google-analytics.com/urchin.js [] []
      [2015-01-07 12:54:47] MCS.INFO: 00041 - https://www.bram.us/2011/09/30/css-regions-and-css-exclusions/ [] []
      [2015-01-07 12:54:47] MCS.INFO: 00042 - https://www.bram.us/2014/06/04/good-looking-shapes-gallery/ [] []
      
      ...
      

      还可以传入包含要扫描的 URL 列表的文件,并将输出更改为 JSON。也支持忽略模式。

      【讨论】:

        猜你喜欢
        • 2015-12-15
        • 1970-01-01
        • 2018-07-23
        • 2020-05-30
        • 2011-02-02
        • 2016-03-14
        • 1970-01-01
        • 2023-03-16
        • 2018-03-05
        相关资源
        最近更新 更多