Skip to main content

A JupyterLab extension that uses cell metadata to define html that is injected into markdown cells.

Project description

aolney_jupyterlab_metadata_html_extension

Github Actions Status Binder

A JupyterLab extension that uses cell metadata to define html that is injected into markdown cells.

This approach overcomes the limitations of JupyterLab markdown cells for certain types of html, such as iframes, that appear to be stripped/sanitized based on the JupyterLab security model.

Using this extension therefore increases the likelihood that an attacker may use a notebook to execute arbitrary code on your computer.

This extension is meant for research purposes only and is not meant for general usage.

Obviously, notebooks with html in the metadata will not render properly without this extension.

Example metadata:

{
    "html": "<iframe class='metadata-html' width='560' height='315' src='https://www.youtube.com/embed/nBrKsT1IvIM' frameborder='0' allow='accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture' allowfullscreen></iframe>"
}

class='metadata-html' will prevent duplicate html injection if switching between notebooks.

[!NOTE] This repo renames and replaces the Jupyter 1.2x version written in F#.

Requirements

  • JupyterLab >= 4.0.0

Install

To install the extension, execute:

pip install aolney_jupyterlab_metadata_html_extension

Uninstall

To remove the extension, execute:

pip uninstall aolney_jupyterlab_metadata_html_extension

Contributing

Development install

Note: You will need NodeJS to build the extension package.

The jlpm command is JupyterLab's pinned version of yarn that is installed with JupyterLab. You may use yarn or npm in lieu of jlpm below.

# Clone the repo to your local environment
# Change directory to the aolney_jupyterlab_metadata_html_extension directory
# Install package in development mode
pip install -e "."
# Link your development version of the extension with JupyterLab
jupyter labextension develop . --overwrite
# Rebuild extension Typescript source after making changes
jlpm build

You can watch the source directory and run JupyterLab at the same time in different terminals to watch for changes in the extension's source and automatically rebuild the extension.

# Watch the source directory in one terminal, automatically rebuilding when needed
jlpm watch
# Run JupyterLab in another terminal
jupyter lab

With the watch command running, every saved change will immediately be built locally and available in your running JupyterLab. Refresh JupyterLab to load the change in your browser (you may need to wait several seconds for the extension to be rebuilt).

By default, the jlpm build command generates the source maps for this extension to make it easier to debug using the browser dev tools. To also generate source maps for the JupyterLab core extensions, you can run the following command:

jupyter lab build --minimize=False

Development uninstall

pip uninstall aolney_jupyterlab_metadata_html_extension

In development mode, you will also need to remove the symlink created by jupyter labextension develop command. To find its location, you can run jupyter labextension list to figure out where the labextensions folder is located. Then you can remove the symlink named @aolney/jupyterlab-metadata-html-extension within that folder.

Packaging the extension

See RELEASE

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file aolney_jupyterlab_metadata_html_extension-0.1.2.tar.gz.

File metadata

File hashes

Hashes for aolney_jupyterlab_metadata_html_extension-0.1.2.tar.gz
Algorithm Hash digest
SHA256 5e2a7e0c6ba21265720fc431d0a4b2a1542c7ea6ab7cf09400aba2b914471aee
MD5 e9b800d7e7ad25cbc08795fb92c858c3
BLAKE2b-256 04dc8e8bfb8fb55756adc164a2042f578bc707bf28cf8937352d7337d20ea65c

See more details on using hashes here.

File details

Details for the file aolney_jupyterlab_metadata_html_extension-0.1.2-py3-none-any.whl.

File metadata

File hashes

Hashes for aolney_jupyterlab_metadata_html_extension-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 ddd5004d63e33c31b5c20e8772535938324910830ec55e2a22ebadc8088196cd
MD5 f63c9b49b67ff798958e3decca7f882d
BLAKE2b-256 0e2542d3c7ac37525c36a5910054034efa65a4fc4f09f759b490569fbc9fa2cd

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page