Protección de remotos de Module Federation
Aprenda a proteger el propio mecanismo de carga de remotos para impedir que los atacantes inyecten o manipulen código federado durante la ejecución.
Protección de remotos de Module Federation es una lección gratuita de Micro Frontends Architecture with Module Federation en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Micro Frontends Architecture with Module Federation, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Micro Frontends Architecture with Module Federation incluye 4 lecciones en total.
Partes de esta lección aún no han sido traducidas y se muestran en inglés.
Remotes Are Live Code
Module Federation fetches and executes remote JavaScript at run time. That power is also a risk: if an attacker controls a remote URL, they can run code inside your app.
The Threat: Remote Tampering
Key threats to the federation layer include:
- A compromised remote host serving malicious code
- Man-in-the-middle modification of
remoteEntry.js - Loading a remote from an unexpected origin
Always Serve Over HTTPS
Loading any remote over plain HTTP allows in-transit tampering. Every remoteEntry.js and chunk must be served over HTTPS, with HSTS enforced.
Allowlist Remote Origins
Do not load remotes from arbitrary URLs. Restrict allowed origins with a Content Security Policy so only trusted hosts can supply scripts.
Content-Security-Policy: script-src 'self' https://cdn.trusted.comSubresource Integrity (SRI)
SRI lets the browser verify a fetched script matches a known hash, rejecting it if it was altered. Pairing SRI with federation guards against tampered remotes.
<script src="/cart/remoteEntry.js"
integrity="sha384-..." crossorigin="anonymous">Validate the Remote Manifest
If you load remote URLs from a manifest, that manifest is a high-value target. Serve it from a trusted origin and validate its contents before using any URL.
Avoid Dynamic Untrusted URLs
Never build a remote URL from user input or untrusted config. An attacker who influences the URL can point your app at malicious code.
// dangerous:
import(userProvidedUrl);
// safe: import from a fixed allowlisted nameIsolate Remotes Where Possible
Because remotes share the same page context, a malicious remote can read the DOM and globals. For untrusted third-party MFEs, consider iframe or sandbox isolation.
Protect Shared State and Tokens
A compromised remote can read shared stores and globals. Never place raw auth tokens on window or in shared state where any remote could harvest them.
Verify Integrity in CI/CD
Generate and pin SRI hashes during the build, and check that deployed remoteEntry files match expected hashes, so a tampered artifact fails verification before users hit it.
Defense in Depth
No single control is enough. Combine HTTPS, CSP allowlists, SRI, manifest validation, and isolation so that bypassing one layer still leaves others protecting the app.
Quick Check
Test your federation-security knowledge.
Recap
You learned to secure federation remotes:
- Remotes execute live code, so the loader is an attack surface
- Always use HTTPS and a CSP script-src allowlist
- Verify integrity with SRI and hash checks in CI
- Never load remotes from untrusted URLs
- Isolate untrusted MFEs and protect tokens
Defense in depth keeps federated code trustworthy.
Preguntas frecuentes
¿La lección «Protección de remotos de Module Federation» es gratis?
Sí — el texto completo de «Protección de remotos de Module Federation» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Micro Frontends Architecture with Module Federation, actualiza a CoddyKit PRO. El curso de Micro Frontends Architecture with Module Federation incluye 4 lecciones en total.
¿Qué aprenderé en «Protección de remotos de Module Federation»?
Aprenda a proteger el propio mecanismo de carga de remotos para impedir que los atacantes inyecten o manipulen código federado durante la ejecución. Practicas Micro Frontends Architecture with Module Federation con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.
¿Necesito experiencia previa para empezar Micro Frontends Architecture with Module Federation?
No se requiere experiencia previa. Micro Frontends Architecture with Module Federation en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.
¿Cuánto tiempo toma la lección «Protección de remotos de Module Federation»?
La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.
¿Puedo escribir y ejecutar código en esta lección de Micro Frontends Architecture with Module Federation?
Sí. Cada lección de Micro Frontends Architecture with Module Federation incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.
Todas las lecciones de este curso
- Autenticación y autorización
- Riesgos de seguridad entre aplicaciones
- Prácticas recomendadas para una federación segura
- Protección de remotos de Module Federation