You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
/docs loads swagger-ui 4.15.5 from cdnjs without SRI #1053
No integrity/SRI./docs is unauthenticated and shares an origin with the web UI, so anything served from that CDN path runs in the app origin. An SRI hash costs nothing here since the version is already pinned.
Vendoring swagger-ui-dist into ui/ and embedding it would solve all three at once. Would you take a PR for that, or is the CDN a deliberate choice to keep the binary small? The CDN stays on purpose (#114). This issue now covers only the version bump and SRI, fixed by #1060.
(Unrelated but in the same file: GET /swagger?base=… splices the query value into the spec JSON unescaped (docs/swagger.go:getSwaggerJSON), so a crafted base can break out of the "host" string. It is self-inflicted only — the page passes window.location.host, never a query param — and the response is sniffed as text/plain, so I do not think it is more than cosmetic. Mentioning it in case you want the value validated anyway.)
Unless @lbellows plans to send a fix, I'd like to take this one: bump swagger-ui to the current 5.x on cdnjs and add SRI hashes, keeping the CDN. I'll open a PR shortly.
changed the title [-]/docs loads swagger-ui 4.15.5 from cdnjs without SRI, and does not work offline[/-][+]/docs loads swagger-ui 4.15.5 from cdnjs without SRI[/+]on Sep 30, 2026
@mehul2409 thanks for offering. I've opened #1060 for this (swagger-ui 5.29.1 + SRI, CDN kept), so you can review that instead. I moved the offline part to #1061.
docs/ui.goserves the Swagger UI page with three external resources from cdnjs:Two things follow from that:
integrity/SRI./docsis unauthenticated and shares an origin with the web UI, so anything served from that CDN path runs in the app origin. An SRI hash costs nothing here since the version is already pinned.3.→ moved to /docs does not work offline: allow a configurable swagger-ui asset URL #1061./docsdoes not work offlineVendoring swagger-ui-dist intoThe CDN stays on purpose (#114). This issue now covers only the version bump and SRI, fixed by #1060.ui/and embedding it would solve all three at once. Would you take a PR for that, or is the CDN a deliberate choice to keep the binary small?(Unrelated but in the same file:
GET /swagger?base=…splices the query value into the spec JSON unescaped (docs/swagger.go:getSwaggerJSON), so a craftedbasecan break out of the"host"string. It is self-inflicted only — the page passeswindow.location.host, never a query param — and the response is sniffed astext/plain, so I do not think it is more than cosmetic. Mentioning it in case you want the value validated anyway.)