Skip to content

/docs loads swagger-ui 4.15.5 from cdnjs without SRI #1053

Description

@lbellows

docs/ui.go serves the Swagger UI page with three external resources from cdnjs:

<link rel="stylesheet" type="text/css" href="https://cdnjs.cloudflare.com/ajax/libs/swagger-ui/4.15.5/swagger-ui.css" >
<script src="https://cdnjs.cloudflare.com/ajax/libs/swagger-ui/4.15.5/swagger-ui-bundle.js"> </script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/swagger-ui/4.15.5/swagger-ui-standalone-preset.js"> </script>

Two things follow from that:

  1. No integrity/SRI. /docs is unauthenticated and shares an origin with the web UI, so anything served from that CDN path runs in the app origin. An SRI hash costs nothing here since the version is already pinned.
  2. 4.15.5 is from 2022, several majors behind swagger-ui 5.x.
    3. /docs does not work offline → moved to /docs does not work offline: allow a configurable swagger-ui asset URL #1061.

Vendoring swagger-ui-dist into ui/ and embedding it would solve all three at once. Would you take a PR for that, or is the CDN a deliberate choice to keep the binary small? The CDN stays on purpose (#114). This issue now covers only the version bump and SRI, fixed by #1060.

(Unrelated but in the same file: GET /swagger?base=… splices the query value into the spec JSON unescaped (docs/swagger.go:getSwaggerJSON), so a crafted base can break out of the "host" string. It is self-inflicted only — the page passes window.location.host, never a query param — and the response is sniffed as text/plain, so I do not think it is more than cosmetic. Mentioning it in case you want the value validated anyway.)

Activity

jmattheis commented on Sep 20, 2026

@jmattheis
Member

It was an explicit choice to reduce binary size => #114.

Using a recent version with integrity sounds good.

mehul2409 commented on Sep 30, 2026

@mehul2409

Unless @lbellows plans to send a fix, I'd like to take this one: bump swagger-ui to the current 5.x on cdnjs and add SRI hashes, keeping the CDN. I'll open a PR shortly.

changed the title [-]/docs loads swagger-ui 4.15.5 from cdnjs without SRI, and does not work offline[/-] [+]/docs loads swagger-ui 4.15.5 from cdnjs without SRI[/+] on Sep 30, 2026

lbellows commented on Sep 30, 2026

@lbellows
ContributorAuthor

@mehul2409 thanks for offering. I've opened #1060 for this (swagger-ui 5.29.1 + SRI, CDN kept), so you can review that instead. I moved the offline part to #1061.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    a:featureNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions