Skip to main content

A JupyterLab extension that uses cell metadata to define html that is injected into markdown cells.

Project description

aolney_jupyterlab_metadata_html_extension

Github Actions Status Binder

A JupyterLab extension that uses cell metadata to define html that is injected into markdown cells.

This approach overcomes the limitations of JupyterLab markdown cells for certain types of html, such as iframes, that appear to be stripped/sanitized based on the JupyterLab security model.

Using this extension therefore increases the likelihood that an attacker may use a notebook to execute arbitrary code on your computer.

This extension is meant for research purposes only and is not meant for general usage.

Obviously, notebooks with html in the metadata will not render properly without this extension.

Example metadata:

{
    "html": "<iframe class='metadata-html' width='560' height='315' src='https://www.youtube.com/embed/nBrKsT1IvIM' frameborder='0' allow='accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture' allowfullscreen></iframe>"
}

class='metadata-html' will prevent duplicate html injection if switching between notebooks.

[!NOTE] This repo renames and replaces the Jupyter 1.2x version written in F#.

Requirements

  • JupyterLab >= 4.0.0

Install

To install the extension, execute:

pip install aolney_jupyterlab_metadata_html_extension

Uninstall

To remove the extension, execute:

pip uninstall aolney_jupyterlab_metadata_html_extension

Contributing

Development install

Note: You will need NodeJS to build the extension package.

The jlpm command is JupyterLab's pinned version of yarn that is installed with JupyterLab. You may use yarn or npm in lieu of jlpm below.

# Clone the repo to your local environment
# Change directory to the aolney_jupyterlab_metadata_html_extension directory
# Install package in development mode
pip install -e "."
# Link your development version of the extension with JupyterLab
jupyter labextension develop . --overwrite
# Rebuild extension Typescript source after making changes
jlpm build

You can watch the source directory and run JupyterLab at the same time in different terminals to watch for changes in the extension's source and automatically rebuild the extension.

# Watch the source directory in one terminal, automatically rebuilding when needed
jlpm watch
# Run JupyterLab in another terminal
jupyter lab

With the watch command running, every saved change will immediately be built locally and available in your running JupyterLab. Refresh JupyterLab to load the change in your browser (you may need to wait several seconds for the extension to be rebuilt).

By default, the jlpm build command generates the source maps for this extension to make it easier to debug using the browser dev tools. To also generate source maps for the JupyterLab core extensions, you can run the following command:

jupyter lab build --minimize=False

Development uninstall

pip uninstall aolney_jupyterlab_metadata_html_extension

In development mode, you will also need to remove the symlink created by jupyter labextension develop command. To find its location, you can run jupyter labextension list to figure out where the labextensions folder is located. Then you can remove the symlink named @aolney/jupyterlab-metadata-html-extension within that folder.

Packaging the extension

See RELEASE

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file aolney_jupyterlab_metadata_html_extension-0.1.0.tar.gz.

File metadata

File hashes

Hashes for aolney_jupyterlab_metadata_html_extension-0.1.0.tar.gz
Algorithm Hash digest
SHA256 f4bec94fa92e428e0483776fa0efa84f16c5a2bc72cbd246ba1fe5aec90446d1
MD5 d6acd1ed9c0c65d557f64a9a2a00afd1
BLAKE2b-256 fa23112cd77ac30945f65856536772dc68d762bf86e2d071328678aaebd2f579

See more details on using hashes here.

File details

Details for the file aolney_jupyterlab_metadata_html_extension-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for aolney_jupyterlab_metadata_html_extension-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 b9567155976f95b58bdc35da920d44626ba6b610d212752d801ab6876d89b7ad
MD5 3cc0c854c2aeae1d1ce9cadb91ebd95e
BLAKE2b-256 e7c46fc1fe663fba31a4d5d41eaa2a0c1fbb8a896f2f303e5a1bd6eec2d45b2d

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page