- CorsAwareResourceRenderer
The CorsAwareResourceRenderer is intended as an extension to the standard script and stylesheet resource renderer in order to add the crossorigin and integrity attributes as a pass-through attribute. Each attribute has its own condition.
The crossorigin attribute is only set when the Resource.getRequestPath() points to another origin than the one of the current request. It will then by default be set to anonymous. Resources which are served from the same origin are left alone, as a crossorigin attribute has no security benefit on those, while it does force the browser into CORS mode, which in turn breaks script loaders which rely on a synchronous XMLHttpRequest to fetch and evaluate a dynamically added script.
The integrity attribute is only set when the ResourceHandler.createResource(String) returns an instance of CDNResource. It will then be set with a base64 encoded sha384 hash of the local content. A CDNResource is returned by a ResourceHandler which you write yourself and which uploads your own resources to your own CDN host, so that the CDN content stays byte for byte identical to the local content. Note that the CDNResourceHandler does not return one, hence the resources remapped by it do get a crossorigin attribute but no integrity attribute.
This includes declarative resources created by <h:outputScript> and <h:outputStylesheet>, annotated resources created by ResourceDependency, combined resources created by CombinedResourceHandler, deferred scripts created by DeferredScript and critical stylesheets created by CriticalStylesheet. Basically any resource which will be served by ResourceHandler.createResource(String).
Installation
You do not need to explicitly register this renderer in your faces-config.xml. It's already automatically registered.
Configuration
Currently only the following context parameter is available: "org.omnifaces.DEFAULT_CROSSORIGIN". This sets the desired value of crossorigin attribute of cross origin resources. Supported values are specified in MDN. An empty string is also allowed, it will then completely skip the task of the current renderer, including the integrity attribute. The default value when the context parameter is not set is anonymous (i.e. no cookies are transferred at all).
Usage
Eveything is automatic. In case you wish to override the default/configured outcome of one of the attributes on a specific resource component, then simply explicitly set it as a passthrough attribute yourself. For example,
<... xmlns:h="jakarta.faces.html" xmlns:a="jakarta.faces.passthrough">
<h:outputScript name="..." a:crossorigin="use-credentials" />