Electron Desktop App Development · Lektion

Schutz vor Risiken durch entfernte Inhalte

Schützen Sie Ihre Electron-App mithilfe von webSecurity, CSP und Navigationskontrollen vor Bedrohungen durch entfernte oder nicht vertrauenswürdige Webinhalte und bauen Sie dabei auf Isolation und Sandboxing auf.

Lektion 4 von 413 Schritte

Schutz vor Risiken durch entfernte Inhalte ist eine kostenlose Electron Desktop App Development-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Electron Desktop App Development-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Electron Desktop App Development-Kurs umfasst insgesamt 4 Lektionen.

Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.

The Danger of Remote Content

Loading remote URLs or untrusted HTML can expose your app to cross-site scripting and code execution. Hardening is essential.

Prefer Local Content

The safest app loads only local files you control. Treat any remote content as hostile until proven otherwise.

Keep webSecurity On

Never disable webSecurity. It enforces the same-origin policy inside your renderer.

new BrowserWindow({
  webPreferences: {
    webSecurity: true
  }
});

Content Security Policy

A CSP restricts what scripts and resources can load, blocking injected code.

<meta http-equiv="Content-Security-Policy" content="default-src 'self'">

Validating a CSP

A strict CSP avoids unsafe-inline and unsafe-eval. You can lint your policy programmatically.

function isStrict(csp) {
  return !csp.includes('unsafe-inline') && !csp.includes('unsafe-eval');
}
console.log(isStrict("default-src 'self'"));

Controlling Navigation

Block unexpected navigation with the will-navigate event, allowing only your trusted origins.

function allowed(url) {
  return url.startsWith('https://myapp.example.com');
}
console.log(allowed('https://evil.com'));

Blocking New Windows

Intercept setWindowOpenHandler to deny or vet any attempt to open new windows from content.

contents.setWindowOpenHandler(({ url }) => {
  return { action: allowed(url) ? 'allow' : 'deny' };
});

Opening Links Safely

Send external links to the OS browser with shell.openExternal instead of loading them inside your app.

Disable Unused Permissions

Use a setPermissionRequestHandler to deny camera, geolocation, and other requests your app does not need.

session.setPermissionRequestHandler((wc, perm, cb) => {
  cb(perm === 'notifications');
});

Avoid Disabling Protections

Flags like allowRunningInsecureContent and nodeIntegration: true on remote content are dangerous. Keep defaults.

Audit Regularly

Run Electron's security checklist and keep Electron updated to inherit Chromium's latest patches.

Quick Check

Test your remote-content hardening knowledge.

Recap

You learned to harden against remote content: prefer local files, keep webSecurity on, enforce a strict CSP, control navigation and window opening, deny unneeded permissions, and audit regularly.

Kostenlos starten

Lerne JavaScript mit einem KI-Tutor — kostenlos

Schreibe und führe echten Code in deinem Browser aus, bekomme sofortige Hilfe von einem 24/7 KI-Tutor und setze dein Lernen im Web oder in der App fort.

Kurse
12
Lektionen
47

Häufig gestellte Fragen

Ist die Lektion „Schutz vor Risiken durch entfernte Inhalte“ kostenlos?

Ja — der vollständige Text von „Schutz vor Risiken durch entfernte Inhalte“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Electron Desktop App Development-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Electron Desktop App Development-Kurs umfasst insgesamt 4 Lektionen.

Was lerne ich in „Schutz vor Risiken durch entfernte Inhalte“?

Schützen Sie Ihre Electron-App mithilfe von webSecurity, CSP und Navigationskontrollen vor Bedrohungen durch entfernte oder nicht vertrauenswürdige Webinhalte und bauen Sie dabei auf Isolation und Sa… Du übst Electron Desktop App Development mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.

Brauche ich Erfahrung, um Electron Desktop App Development zu starten?

Keine Vorkenntnisse erforderlich. Electron Desktop App Development auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.

Wie lange dauert die Lektion „Schutz vor Risiken durch entfernte Inhalte“?

Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.

Kann ich in dieser Electron Desktop App Development-Lektion Code schreiben und ausführen?

Ja. Jede Electron Desktop App Development-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.

Alle Lektionen in diesem Kurs

  1. Sichere IPC-Muster
  2. Context Isolation und Preload-Skripte
  3. Renderer-Prozess sandbo eingebettet
  4. Schutz vor Risiken durch entfernte Inhalte
← Zurück zu Electron Desktop App Development