Context Isolation und Preload-Skripte
Verstehen und nutzen Sie Context Isolation, um Ihren Renderer-Prozess vor bösartigen Skripten zu schützen, und verwenden Sie Preload-Skripte für die sichere Bereitstellung von APIs.
Context Isolation und Preload-Skripte ist eine kostenlose Electron Desktop App Development-Lektion auf CoddyKit. Dies ist Lektion 2 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Electron Desktop App Development-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Electron Desktop App Development-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
Renderer Process Risks
In Electron, your application's user interface runs in a renderer process. This process is essentially a Chromium web page, meaning it's susceptible to common web vulnerabilities like Cross-Site Scripting (XSS).
- Malicious scripts injected into your web content could potentially gain access to powerful Node.js APIs.
- This direct access could lead to system-level operations being performed without your knowledge or consent.
- Protecting the renderer is crucial for app security.
What is Context Isolation?
Context Isolation is a fundamental security feature in Electron. When enabled, it ensures that the JavaScript context of your web page is completely separate from Electron's internal APIs and Node.js environment.
- It's like having two distinct JavaScript worlds within the same renderer process.
- One world for your web content, and another for Electron/Node.js.
- This separation prevents your web page's scripts from directly accessing sensitive APIs.
Good news: Context Isolation is enabled by default since Electron 12!
Two JavaScript Worlds
Imagine your renderer process has two invisible layers:
- The Web Page Context: This is where your
index.html, its scripts, and any loaded libraries (like React or Vue) run. It behaves just like a regular browser tab. - The Electron/Node.js Context: This is where Electron's internal modules and Node.js APIs (like
fsfor file system access) live.
Context Isolation ensures these two worlds cannot directly interact with each other's global objects (like window or document), preventing unauthorized access.
Bridging Isolated Contexts
While isolation is great for security, sometimes your web page needs to interact with native desktop features. This is where preload scripts come in.
- A preload script runs before your web page loads, but within the Electron/Node.js context.
- It has access to both Node.js APIs and the web page's
windowobject (before isolation takes full effect). - However, to securely expose APIs to the isolated web page, we use a special tool called
contextBridge.
Loading a Preload Script
To use a preload script, you must specify its path when creating your BrowserWindow in the main process. Remember to keep contextIsolation set to true for security.
Try running this basic setup:
const { app, BrowserWindow } = require('electron');
const path = require('path');
function createWindow () {
const mainWindow = new BrowserWindow({
width: 800,
height: 600,
webPreferences: {
preload: path.join(__dirname, 'preload.js'),
contextIsolation: true // Crucial for security!
}
});
mainWindow.loadFile('index.html');
}
app.whenReady().then(() => {
createWindow();
app.on('activate', function () {
if (BrowserWindow.getAllWindows().length === 0) createWindow();
});
});
app.on('window-all-closed', function () {
if (process.platform !== 'darwin') app.quit();
});Secure API Exposure
The contextBridge module is your best friend for securely exposing functionality from your preload script to the renderer's isolated web context.
- It acts as a secure, one-way bridge.
- You define what functions or data you want to expose.
contextBridgeensures that only these defined APIs are available and that data passed between contexts is properly sanitized.
This prevents malicious scripts in the web page from tampering with your exposed APIs or gaining direct access to Node.js.
Crafting Your Preload Script
Inside your preload.js, you'll use contextBridge.exposeInMainWorld(). This method takes two arguments: a key (how the API will be named in the renderer's window object) and an object containing the functions or values you want to expose.
preload.js:
const { contextBridge } = require('electron');
contextBridge.exposeInMainWorld('myAPI', {
// Expose a simple function
sendNotification: (message) => {
// In a real app, you'd use ipcRenderer.send to talk to main process
console.log(`Preload script sending notification: ${message}`);
// Example: new Notification('Title', { body: message });
},
// Expose a value
version: process.versions.electron
});Accessing Exposed APIs
Once your preload script has exposed an API using contextBridge, your web page's JavaScript can safely access it via the window object, under the key you specified.
index.html (or a script loaded by it):
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8">
<title>My Electron App</title>
</head>
<body>
<h1>Welcome!</h1>
<p>Electron Version: <span id="electron-version"></span></p>
<button id="notify-btn">Send Notification</button>
<script>
// Access the exposed API
window.addEventListener('DOMContentLoaded', () => {
document.getElementById('electron-version').innerText = window.myAPI.version;
document.getElementById('notify-btn').addEventListener('click', () => {
window.myAPI.sendNotification('Hello from the renderer!');
});
});
</script>
</body>
</html>Full Example in Action
Here's the complete main.js for our app. To run this example, create three files: main.js (below), preload.js (content from Scene 7), and index.html (content from Scene 8) in the same directory.
When you run main.js, it will load index.html. The index.html then uses the myAPI object exposed by preload.js to display the Electron version and trigger a 'notification' (logged to console in this simple example).
const { app, BrowserWindow } = require('electron');
const path = require('path');
function createWindow () {
const mainWindow = new BrowserWindow({
width: 800,
height: 600,
webPreferences: {
preload: path.join(__dirname, 'preload.js'),
contextIsolation: true // Keep this true!
}
});
mainWindow.loadFile('index.html');
// Open DevTools to see console logs from preload and renderer
mainWindow.webContents.openDevTools();
}
app.whenReady().then(() => {
createWindow();
app.on('activate', function () {
if (BrowserWindow.getAllWindows().length === 0) createWindow();
});
});
app.on('window-all-closed', function () {
if (process.platform !== 'darwin') app.quit();
});Context Check
Time to test your understanding of context isolation and preload scripts!
Secure Foundations
You've learned how to secure your Electron application's renderer process!
- Context Isolation is key to preventing direct access between untrusted web content and powerful Node.js APIs.
- Preload scripts run in an isolated environment, allowing you to bridge this gap safely.
contextBridgeis the secure method within preload scripts to expose carefully selected APIs to your web content.
By using these features, you build a robust and secure foundation for your Electron desktop applications. Great job!
Häufig gestellte Fragen
Ist die Lektion „Context Isolation und Preload-Skripte“ kostenlos?
Ja — der vollständige Text von „Context Isolation und Preload-Skripte“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Electron Desktop App Development-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Electron Desktop App Development-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Context Isolation und Preload-Skripte“?
Verstehen und nutzen Sie Context Isolation, um Ihren Renderer-Prozess vor bösartigen Skripten zu schützen, und verwenden Sie Preload-Skripte für die sichere Bereitstellung von APIs. Du übst Electron Desktop App Development mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um Electron Desktop App Development zu starten?
Keine Vorkenntnisse erforderlich. Electron Desktop App Development auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 2 von 4.
Wie lange dauert die Lektion „Context Isolation und Preload-Skripte“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser Electron Desktop App Development-Lektion Code schreiben und ausführen?
Ja. Jede Electron Desktop App Development-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Sichere IPC-Muster
- Context Isolation und Preload-Skripte
- Renderer-Prozess sandbo eingebettet
- Schutz vor Risiken durch entfernte Inhalte