web-worker-csp

command
v1.5.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 23, 2026 License: MIT Imports: 3 Imported by: 0

README

Web Worker CSP Example

This example demonstrates how to enable Web Worker support with Content Security Policy (CSP) in HyperServe.

What this example shows

  • How to enable Web Worker support using WithCSPWebWorkerSupport()
  • How to create Web Workers using blob: URLs
  • How CSP headers are configured to allow Web Workers
  • Simulation of real-world usage (like Tone.js audio libraries)

The Problem

Many modern web applications use Web Workers for performance optimization. Libraries like:

  • Tone.js - Web Audio API library for audio synthesis
  • PDF.js - PDF rendering library
  • Custom audio/video processing libraries

These libraries create Web Workers using blob: URLs, which are blocked by default by Content Security Policy (CSP) for security reasons.

The Solution

HyperServe provides WithCSPWebWorkerSupport() to enable blob: URLs in the CSP worker-src and child-src directives.

Running the Example

cd examples/web-worker-csp
go run main.go

Visit: http://localhost:8080

What to Test

  1. Test Web Worker - Creates a simple Web Worker using blob: URL
  2. Test Tone.js (Simulated) - Simulates how Tone.js creates timing workers
  3. Show CSP Headers - Displays the actual CSP headers sent by the server

Key Code

// Enable Web Worker support
srv, err := server.NewServer(
    server.WithCSPWebWorkerSupport(),
)

// Apply security headers with Web Worker support
srv.AddMiddleware("*", server.HeadersMiddleware(srv.Options))

CSP Configuration

When Web Worker support is enabled, the CSP header includes:

  • worker-src 'self' blob:
  • child-src 'self' blob:

When disabled (default), Web Workers with blob: URLs will be blocked.

Security Note

Web Worker support is disabled by default for security reasons. Only enable it when your application specifically needs to use Web Workers with blob: URLs.

Real-World Usage

This feature is essential for:

  • Digital Audio Workstations (DAWs) using Tone.js
  • PDF viewers using PDF.js
  • Video/audio processing applications
  • Any application using Web Workers for performance optimization

Documentation

The Go Gopher

There is no documentation for this package.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL