การเสริมความปลอดภัยจากความเสี่ยงของเนื้อหาระยะไกล
ปกป้องแอป Electron จากภัยคุกคามที่มาจากเนื้อหาเว็บระยะไกลหรือไม่น่าเชื่อถือด้วย webSecurity, CSP และการควบคุมการนำทาง โดยต่อยอดจากการแยกส่วนและแซนด์บ็อกซ์
การเสริมความปลอดภัยจากความเสี่ยงของเนื้อหาระยะไกล เป็นบทเรียน Electron Desktop App Development ฟรีบน CoddyKit นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Electron Desktop App Development และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Electron Desktop App Development มีบทเรียนทั้งหมด 4 บทเรียน
บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ
The Danger of Remote Content
Loading remote URLs or untrusted HTML can expose your app to cross-site scripting and code execution. Hardening is essential.
Prefer Local Content
The safest app loads only local files you control. Treat any remote content as hostile until proven otherwise.
Keep webSecurity On
Never disable webSecurity. It enforces the same-origin policy inside your renderer.
new BrowserWindow({
webPreferences: {
webSecurity: true
}
});Content Security Policy
A CSP restricts what scripts and resources can load, blocking injected code.
<meta http-equiv="Content-Security-Policy" content="default-src 'self'">Validating a CSP
A strict CSP avoids unsafe-inline and unsafe-eval. You can lint your policy programmatically.
function isStrict(csp) {
return !csp.includes('unsafe-inline') && !csp.includes('unsafe-eval');
}
console.log(isStrict("default-src 'self'"));Controlling Navigation
Block unexpected navigation with the will-navigate event, allowing only your trusted origins.
function allowed(url) {
return url.startsWith('https://myapp.example.com');
}
console.log(allowed('https://evil.com'));Blocking New Windows
Intercept setWindowOpenHandler to deny or vet any attempt to open new windows from content.
contents.setWindowOpenHandler(({ url }) => {
return { action: allowed(url) ? 'allow' : 'deny' };
});Opening Links Safely
Send external links to the OS browser with shell.openExternal instead of loading them inside your app.
Disable Unused Permissions
Use a setPermissionRequestHandler to deny camera, geolocation, and other requests your app does not need.
session.setPermissionRequestHandler((wc, perm, cb) => {
cb(perm === 'notifications');
});Avoid Disabling Protections
Flags like allowRunningInsecureContent and nodeIntegration: true on remote content are dangerous. Keep defaults.
Audit Regularly
Run Electron's security checklist and keep Electron updated to inherit Chromium's latest patches.
Quick Check
Test your remote-content hardening knowledge.
Recap
You learned to harden against remote content: prefer local files, keep webSecurity on, enforce a strict CSP, control navigation and window opening, deny unneeded permissions, and audit regularly.
คำถามที่พบบ่อย
บทเรียน “การเสริมความปลอดภัยจากความเสี่ยงของเนื้อหาระยะไกล” ฟรีหรือไม่
ใช่ — ข้อความเต็มของ “การเสริมความปลอดภัยจากความเสี่ยงของเนื้อหาระยะไกล” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Electron Desktop App Development ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Electron Desktop App Development มีบทเรียนทั้งหมด 4 บทเรียน
คุณจะเรียนรู้อะไรในบทเรียน “การเสริมความปลอดภัยจากความเสี่ยงของเนื้อหาระยะไกล”
ปกป้องแอป Electron จากภัยคุกคามที่มาจากเนื้อหาเว็บระยะไกลหรือไม่น่าเชื่อถือด้วย webSecurity, CSP และการควบคุมการนำทาง โดยต่อยอดจากการแยกส่วนและแซนด์บ็อกซ์ คุณปฏิบัติ Electron Desktop App Development ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน
คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Electron Desktop App Development หรือไม่
ไม่จำเป็นต้องมีประสบการณ์มาก่อน Electron Desktop App Development บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน
บทเรียน “การเสริมความปลอดภัยจากความเสี่ยงของเนื้อหาระยะไกล” ใช้เวลานานแค่ไหน
บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย
ฉันเขียนและรันโค้ดในบทเรียน Electron Desktop App Development นี้ได้ไหม
ได้ บทเรียน Electron Desktop App Development ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ
บทเรียนทั้งหมดในหลักสูตรนี้
- รูปแบบ IPC ที่ปลอดภัย
- การแยกบริบทและสคริปต์โหลดล่วงหน้า
- การทำแซนด์บ็อกซ์กระบวนการแสดงผล
- การเสริมความปลอดภัยจากความเสี่ยงของเนื้อหาระยะไกล