Schutz vor Risiken durch entfernte Inhalte
Schützen Sie Ihre Electron-App mithilfe von webSecurity, CSP und Navigationskontrollen vor Bedrohungen durch entfernte oder nicht vertrauenswürdige Webinhalte und bauen Sie dabei auf Isolation und Sandboxing auf.
Schutz vor Risiken durch entfernte Inhalte ist eine kostenlose Electron Desktop App Development-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Electron Desktop App Development-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Electron Desktop App Development-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
The Danger of Remote Content
Loading remote URLs or untrusted HTML can expose your app to cross-site scripting and code execution. Hardening is essential.
Prefer Local Content
The safest app loads only local files you control. Treat any remote content as hostile until proven otherwise.
Keep webSecurity On
Never disable webSecurity. It enforces the same-origin policy inside your renderer.
new BrowserWindow({
webPreferences: {
webSecurity: true
}
});Content Security Policy
A CSP restricts what scripts and resources can load, blocking injected code.
<meta http-equiv="Content-Security-Policy" content="default-src 'self'">Validating a CSP
A strict CSP avoids unsafe-inline and unsafe-eval. You can lint your policy programmatically.
function isStrict(csp) {
return !csp.includes('unsafe-inline') && !csp.includes('unsafe-eval');
}
console.log(isStrict("default-src 'self'"));Controlling Navigation
Block unexpected navigation with the will-navigate event, allowing only your trusted origins.
function allowed(url) {
return url.startsWith('https://myapp.example.com');
}
console.log(allowed('https://evil.com'));Blocking New Windows
Intercept setWindowOpenHandler to deny or vet any attempt to open new windows from content.
contents.setWindowOpenHandler(({ url }) => {
return { action: allowed(url) ? 'allow' : 'deny' };
});Opening Links Safely
Send external links to the OS browser with shell.openExternal instead of loading them inside your app.
Disable Unused Permissions
Use a setPermissionRequestHandler to deny camera, geolocation, and other requests your app does not need.
session.setPermissionRequestHandler((wc, perm, cb) => {
cb(perm === 'notifications');
});Avoid Disabling Protections
Flags like allowRunningInsecureContent and nodeIntegration: true on remote content are dangerous. Keep defaults.
Audit Regularly
Run Electron's security checklist and keep Electron updated to inherit Chromium's latest patches.
Quick Check
Test your remote-content hardening knowledge.
Recap
You learned to harden against remote content: prefer local files, keep webSecurity on, enforce a strict CSP, control navigation and window opening, deny unneeded permissions, and audit regularly.
Lerne JavaScript mit einem KI-Tutor — kostenlos
Schreibe und führe echten Code in deinem Browser aus, bekomme sofortige Hilfe von einem 24/7 KI-Tutor und setze dein Lernen im Web oder in der App fort.
- Kurse
- 12
- Lektionen
- 47
Häufig gestellte Fragen
Ist die Lektion „Schutz vor Risiken durch entfernte Inhalte“ kostenlos?
Ja — der vollständige Text von „Schutz vor Risiken durch entfernte Inhalte“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Electron Desktop App Development-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Electron Desktop App Development-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Schutz vor Risiken durch entfernte Inhalte“?
Schützen Sie Ihre Electron-App mithilfe von webSecurity, CSP und Navigationskontrollen vor Bedrohungen durch entfernte oder nicht vertrauenswürdige Webinhalte und bauen Sie dabei auf Isolation und Sa… Du übst Electron Desktop App Development mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um Electron Desktop App Development zu starten?
Keine Vorkenntnisse erforderlich. Electron Desktop App Development auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.
Wie lange dauert die Lektion „Schutz vor Risiken durch entfernte Inhalte“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser Electron Desktop App Development-Lektion Code schreiben und ausführen?
Ja. Jede Electron Desktop App Development-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Sichere IPC-Muster
- Context Isolation und Preload-Skripte
- Renderer-Prozess sandbo eingebettet
- Schutz vor Risiken durch entfernte Inhalte