Electron Desktop App Development · درس

تحصين التطبيق ضد مخاطر المحتوى البعيد

احمِ تطبيق Electron من التهديدات التي يسببها محتوى الويب البعيد أو غير الموثوق باستخدام webSecurity وCSP وعناصر التحكم في التنقل، بالاعتماد على العزل ووضع الحماية.

الدرس 4 من 413 خطوة

تحصين التطبيق ضد مخاطر المحتوى البعيد درس مجاني في Electron Desktop App Development على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Electron Desktop App Development، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Electron Desktop App Development 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

The Danger of Remote Content

Loading remote URLs or untrusted HTML can expose your app to cross-site scripting and code execution. Hardening is essential.

Prefer Local Content

The safest app loads only local files you control. Treat any remote content as hostile until proven otherwise.

Keep webSecurity On

Never disable webSecurity. It enforces the same-origin policy inside your renderer.

new BrowserWindow({
  webPreferences: {
    webSecurity: true
  }
});

Content Security Policy

A CSP restricts what scripts and resources can load, blocking injected code.

<meta http-equiv="Content-Security-Policy" content="default-src 'self'">

Validating a CSP

A strict CSP avoids unsafe-inline and unsafe-eval. You can lint your policy programmatically.

function isStrict(csp) {
  return !csp.includes('unsafe-inline') && !csp.includes('unsafe-eval');
}
console.log(isStrict("default-src 'self'"));

Controlling Navigation

Block unexpected navigation with the will-navigate event, allowing only your trusted origins.

function allowed(url) {
  return url.startsWith('https://myapp.example.com');
}
console.log(allowed('https://evil.com'));

Blocking New Windows

Intercept setWindowOpenHandler to deny or vet any attempt to open new windows from content.

contents.setWindowOpenHandler(({ url }) => {
  return { action: allowed(url) ? 'allow' : 'deny' };
});

Opening Links Safely

Send external links to the OS browser with shell.openExternal instead of loading them inside your app.

Disable Unused Permissions

Use a setPermissionRequestHandler to deny camera, geolocation, and other requests your app does not need.

session.setPermissionRequestHandler((wc, perm, cb) => {
  cb(perm === 'notifications');
});

Avoid Disabling Protections

Flags like allowRunningInsecureContent and nodeIntegration: true on remote content are dangerous. Keep defaults.

Audit Regularly

Run Electron's security checklist and keep Electron updated to inherit Chromium's latest patches.

Quick Check

Test your remote-content hardening knowledge.

Recap

You learned to harden against remote content: prefer local files, keep webSecurity on, enforce a strict CSP, control navigation and window opening, deny unneeded permissions, and audit regularly.

البدء مجانًا

تعلم JavaScript مع معلم ذكاء اصطناعي — مجانًا

اكتب وقم بتشغيل أكوادك الفعلية في المتصفح، واحصل على مساعدة فورية من معلم ذكاء اصطناعي متاح 24/7، واستمر من حيث توقفت على الويب أو في التطبيق.

الدورات
12
الدروس
47

الأسئلة الشائعة

هل درس «تحصين التطبيق ضد مخاطر المحتوى البعيد» مجاني؟

نعم — نص درس «تحصين التطبيق ضد مخاطر المحتوى البعيد» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Electron Desktop App Development، انتقل إلى CoddyKit PRO. تتضمن دورة Electron Desktop App Development 4 دروس في المجموع.

ماذا ستتعلم في «تحصين التطبيق ضد مخاطر المحتوى البعيد»؟

احمِ تطبيق Electron من التهديدات التي يسببها محتوى الويب البعيد أو غير الموثوق باستخدام webSecurity وCSP وعناصر التحكم في التنقل، بالاعتماد على العزل ووضع الحماية. تتمرن على Electron Desktop App Development مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Electron Desktop App Development؟

لا تُشترط خبرة سابقة. Electron Desktop App Development على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «تحصين التطبيق ضد مخاطر المحتوى البعيد»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Electron Desktop App Development هذا؟

نعم. كل درس في Electron Desktop App Development يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. أنماط IPC الآمنة
  2. عزل السياق ونصوص التحميل المسبق
  3. وضع الحماية لعملية العرض
  4. تحصين التطبيق ضد مخاطر المحتوى البعيد
← العودة إلى Electron Desktop App Development