Zabezpieczanie aplikacji zdalnych Module Federation
Dowiedz się, jak chronić sam mechanizm ładowania aplikacji zdalnych, uniemożliwiając atakującym wstrzykiwanie lub modyfikowanie federowanego kodu w czasie działania.
Zabezpieczanie aplikacji zdalnych Module Federation to bezpłatna lekcja Micro Frontends Architecture with Module Federation na CoddyKit. To lekcja 4 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Micro Frontends Architecture with Module Federation, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Micro Frontends Architecture with Module Federation zawiera 4 lekcji w sumie.
Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.
Remotes Are Live Code
Module Federation fetches and executes remote JavaScript at run time. That power is also a risk: if an attacker controls a remote URL, they can run code inside your app.
The Threat: Remote Tampering
Key threats to the federation layer include:
- A compromised remote host serving malicious code
- Man-in-the-middle modification of
remoteEntry.js - Loading a remote from an unexpected origin
Always Serve Over HTTPS
Loading any remote over plain HTTP allows in-transit tampering. Every remoteEntry.js and chunk must be served over HTTPS, with HSTS enforced.
Allowlist Remote Origins
Do not load remotes from arbitrary URLs. Restrict allowed origins with a Content Security Policy so only trusted hosts can supply scripts.
Content-Security-Policy: script-src 'self' https://cdn.trusted.comSubresource Integrity (SRI)
SRI lets the browser verify a fetched script matches a known hash, rejecting it if it was altered. Pairing SRI with federation guards against tampered remotes.
<script src="/cart/remoteEntry.js"
integrity="sha384-..." crossorigin="anonymous">Validate the Remote Manifest
If you load remote URLs from a manifest, that manifest is a high-value target. Serve it from a trusted origin and validate its contents before using any URL.
Avoid Dynamic Untrusted URLs
Never build a remote URL from user input or untrusted config. An attacker who influences the URL can point your app at malicious code.
// dangerous:
import(userProvidedUrl);
// safe: import from a fixed allowlisted nameIsolate Remotes Where Possible
Because remotes share the same page context, a malicious remote can read the DOM and globals. For untrusted third-party MFEs, consider iframe or sandbox isolation.
Protect Shared State and Tokens
A compromised remote can read shared stores and globals. Never place raw auth tokens on window or in shared state where any remote could harvest them.
Verify Integrity in CI/CD
Generate and pin SRI hashes during the build, and check that deployed remoteEntry files match expected hashes, so a tampered artifact fails verification before users hit it.
Defense in Depth
No single control is enough. Combine HTTPS, CSP allowlists, SRI, manifest validation, and isolation so that bypassing one layer still leaves others protecting the app.
Quick Check
Test your federation-security knowledge.
Recap
You learned to secure federation remotes:
- Remotes execute live code, so the loader is an attack surface
- Always use HTTPS and a CSP script-src allowlist
- Verify integrity with SRI and hash checks in CI
- Never load remotes from untrusted URLs
- Isolate untrusted MFEs and protect tokens
Defense in depth keeps federated code trustworthy.
Ucz się JavaScript dzięki korepetycjom AI — za darmo
Pisz i uruchamiaj kod w przeglądarce, otrzymuj natychmiastową pomoc od korepetytora AI dostępnego 24/7 i kontynuuj naukę w sieci lub w aplikacji.
- Kursy
- 12
- Lekcje
- 48
Często zadawane pytania
Czy lekcja „Zabezpieczanie aplikacji zdalnych Module Federation” jest bezpłatna?
Tak — pełny tekst „Zabezpieczanie aplikacji zdalnych Module Federation” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Micro Frontends Architecture with Module Federation, przejdź na CoddyKit PRO. Kurs Micro Frontends Architecture with Module Federation zawiera 4 lekcji w sumie.
Co nauczysz się w „Zabezpieczanie aplikacji zdalnych Module Federation”?
Dowiedz się, jak chronić sam mechanizm ładowania aplikacji zdalnych, uniemożliwiając atakującym wstrzykiwanie lub modyfikowanie federowanego kodu w czasie działania. Ćwiczysz Micro Frontends Architecture with Module Federation z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.
Czy potrzebuję doświadczenia, aby zacząć Micro Frontends Architecture with Module Federation?
Nie wymagamy żadnego doświadczenia. Micro Frontends Architecture with Module Federation w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 4 z 4.
Ile czasu zajmuje lekcja „Zabezpieczanie aplikacji zdalnych Module Federation”?
Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.
Czy mogę pisać i uruchamiać kod w tej lekcji Micro Frontends Architecture with Module Federation?
Tak. Każda lekcja Micro Frontends Architecture with Module Federation zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.
Wszystkie lekcje w tym kursie
- Uwierzytelnianie i autoryzacja
- Ryzyka bezpieczeństwa między aplikacjami
- Najlepsze praktyki bezpiecznej federacji
- Zabezpieczanie aplikacji zdalnych Module Federation