{"id":987516110,"date":"2024-01-12T22:36:17","date_gmt":"2024-01-12T22:36:17","guid":{"rendered":"https:\/\/workspace.trace.pt\/extending-trusted-types-to-gmail\/"},"modified":"2024-01-12T22:36:17","modified_gmt":"2024-01-12T22:36:17","slug":"extending-trusted-types-to-gmail","status":"publish","type":"post","link":"https:\/\/workspace.trace.pt\/en\/extending-trusted-types-to-gmail\/","title":{"rendered":"Extending Trusted Types to Gmail"},"content":{"rendered":"<h3>What\u2019s changing<\/h3>\n<div><a href=\"https:\/\/workspaceupdates.googleblog.com\/2023\/02\/trusted-types-in-google-workspace.html\">Last year,<\/a> we improved the client-side security of Google Docs, Sheets, Slides, Forms, Sites, Drawings, Drive, and Calendar with <a href=\"https:\/\/web.dev\/trusted-types\/\">Trusted Types<\/a>. This browser-based runtime feature limits the uses of <a href=\"https:\/\/www.w3.org\/TR\/trusted-types\/#injection-sinks\">Document Object Model<\/a>\u00a0(DOM) APIs that are used by the apps listed above or third-party extensions. Trusted Types also reduce the possibility of Document Object Model Cross Site Scripting (<a href=\"https:\/\/owasp.org\/www-community\/attacks\/DOM_Based_XSS\">DOM XSS<\/a>), which continues to be one of the most critical threats to web security.\u00a0<\/div>\n<div><\/div>\n<div>DOM XSS occurs when a cyber attacker injects malicious code into a web page, which can then be executed by the victim&#8217;s browser. This can allow the cyber attacker to steal cookies, hijack sessions, and even take control of the victim&#8217;s computer.\u00a0<\/div>\n<div><\/div>\n<div>To defend against this, we\u2019re excited to announce the expansion of Trusted Types to Gmail. This will provide a defense against DOM XSS and further enhances our advanced data protection controls to keep users and data safe across more of the apps they use everyday.\u00a0<\/div>\n<div><\/div>\n<div><\/div>\n<h3>Who\u2019s impacted\u00a0<\/h3>\n<div>Developers (relying on any Chrome extensions that modify DOM APIs.)\u00a0<\/div>\n<div><\/div>\n<div><\/div>\n<h3>Additional details\u00a0<\/h3>\n<div>This new enforcement mode will require third-party extensions to use <a href=\"https:\/\/web.dev\/trusted-types\/#fix-the-violations\">typed objects instead of strings<\/a> when assigning values to DOM APIs. Once Trusted Types are fully enforced, the Trusted Types directive will be present in the Content Security Policy (CSP) header:\u00a0<\/div>\n<div><\/div>\n<div><span>Content-Security-Policy: require-trusted-types-for &#8216;script&#8217;;report-uri https:\/\/mail.google.com\/mail\/cspreport\u00a0<\/span><\/div>\n<div><\/div>\n<div><\/div>\n<h3>Getting started\u00a0<\/h3>\n<div>Admins: There is no admin control for this feature.\u00a0Developers:\u00a0To make code Trusted Types compliant, signal to the browser that data being used within the context of these DOM APIs is trustworthy by creating a Trusted Type special object.\u00a0There are several ways to be Trusted Types compliant, such as <a href=\"https:\/\/web.dev\/articles\/trusted-types#rewrite_the_offending_code\">removing the offending code<\/a>, using a library (such as <a href=\"https:\/\/github.com\/google\/safevalues\">safevalues<\/a> or <a href=\"https:\/\/github.com\/cure53\/DOMPurify#what-about-dompurify-and-trusted-types\">DOMPurify<\/a>), or <a href=\"https:\/\/web.dev\/articles\/trusted-types#create_a_trusted_type_policy\">creating a Trusted Types policy<\/a>. To ensure a seamless experience for users, we recommend employing these techniques before Trusted Types enforcement is rolled out. Failure to make code Trusted Types compliant may cause feature breakages for third-party extensions as their DOM manipulations will be blocked by the browser.\u00a0End users: There is no end user setting for this feature.\u00a0<\/div>\n<div><\/div>\n<h3>Rollout pace\u00a0<\/h3>\n<div><a href=\"https:\/\/support.google.com\/a\/answer\/172177\">Rapid Release domains:<\/a> Extended rollout (potentially longer than 15 days for feature visibility) starting on February 12, 2024\u00a0<a href=\"https:\/\/support.google.com\/a\/answer\/172177\">Scheduled Release domains:<\/a> Gradual rollout (up to 15 days for feature visibility) starting on March 11, 2024\u00a0<\/div>\n<div><\/div>\n<h3>Availability\u00a0<\/h3>\n<div>Available to all Google Workspace customers and users with personal Google Accounts\u00a0<\/div>\n<div><\/div>\n<h3>Resources\u00a0<\/h3>\n<div><a href=\"https:\/\/developer.chrome.com\/blog\/csp-issues\/\">Google Help: Implement CSP and Trusted Types debugging in Chrome DevTools.<\/a><\/div>","protected":false},"excerpt":{"rendered":"<p>What\u2019s changing Last year, we improved the client-side security of Google Docs, Sheets, Slides, Forms, Sites, Drawings, Drive, and Calendar with Trusted Types. This browser-based runtime feature limits the uses of Document Object Model\u00a0(DOM) APIs that are used by the apps listed above or third-party extensions. Trusted Types also reduce the possibility of Document Object [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-987516110","post","type-post","status-publish","format-standard","hentry","category-noticias"],"acf":[],"_links":{"self":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts\/987516110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/comments?post=987516110"}],"version-history":[{"count":0,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/posts\/987516110\/revisions"}],"wp:attachment":[{"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/media?parent=987516110"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/categories?post=987516110"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workspace.trace.pt\/en\/wp-json\/wp\/v2\/tags?post=987516110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}