Securing JavaScript applications within theSpotify web player
Fredrik Gustafsson · KTH Publication Database DiVA (KTH Royal Institute of Technology) · 2014
Developing bug free software is extremely difficult and bugsin a web application can easily lead to security vulnerabilities.Building APIs and opening up your platform has beenproven to add a lot of business value and Spotify has recentlyreleased a JavaScript API that allows third partydevelopers to develop applications for the Desktop basedmusic player.In this thesis we design new security mechanisms forSpotify’s web-based music player in order to make it morerobust against attacks stemming from code injection and,potentially malicious, third party developers.We do this by designing a secure way for transferringthird party application metadata via untrusted JavaScriptcode and implementing the Content-Security-Policy, a relativelynew web standard, for third party applications andthe web player itself.We then propose additions to the Content-Security-Policy web standard that could further improve the securityof modern web applications.