Skip to main content

A JupyterLab extension that uses cell metadata to define html that is injected into markdown cells.

Project description

aolney_jupyterlab_metadata_html_extension

Github Actions Status Binder

A JupyterLab extension that uses cell metadata to define html that is injected into markdown cells.

This approach overcomes the limitations of JupyterLab markdown cells for certain types of html, such as iframes, that appear to be stripped/sanitized based on the JupyterLab security model.

Using this extension therefore increases the likelihood that an attacker may use a notebook to execute arbitrary code on your computer.

This extension is meant for research purposes only and is not meant for general usage.

Obviously, notebooks with html in the metadata will not render properly without this extension.

Example metadata:

{
    "html": "<iframe class='metadata-html' width='560' height='315' src='https://www.youtube.com/embed/nBrKsT1IvIM' frameborder='0' allow='accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture' allowfullscreen></iframe>"
}

class='metadata-html' will prevent duplicate html injection if switching between notebooks.

[!NOTE] This repo renames and replaces the Jupyter 1.2x version written in F#.

Requirements

  • JupyterLab >= 4.0.0

Install

To install the extension, execute:

pip install aolney_jupyterlab_metadata_html_extension

Uninstall

To remove the extension, execute:

pip uninstall aolney_jupyterlab_metadata_html_extension

Contributing

Development install

Note: You will need NodeJS to build the extension package.

The jlpm command is JupyterLab's pinned version of yarn that is installed with JupyterLab. You may use yarn or npm in lieu of jlpm below.

# Clone the repo to your local environment
# Change directory to the aolney_jupyterlab_metadata_html_extension directory
# Install package in development mode
pip install -e "."
# Link your development version of the extension with JupyterLab
jupyter labextension develop . --overwrite
# Rebuild extension Typescript source after making changes
jlpm build

You can watch the source directory and run JupyterLab at the same time in different terminals to watch for changes in the extension's source and automatically rebuild the extension.

# Watch the source directory in one terminal, automatically rebuilding when needed
jlpm watch
# Run JupyterLab in another terminal
jupyter lab

With the watch command running, every saved change will immediately be built locally and available in your running JupyterLab. Refresh JupyterLab to load the change in your browser (you may need to wait several seconds for the extension to be rebuilt).

By default, the jlpm build command generates the source maps for this extension to make it easier to debug using the browser dev tools. To also generate source maps for the JupyterLab core extensions, you can run the following command:

jupyter lab build --minimize=False

Development uninstall

pip uninstall aolney_jupyterlab_metadata_html_extension

In development mode, you will also need to remove the symlink created by jupyter labextension develop command. To find its location, you can run jupyter labextension list to figure out where the labextensions folder is located. Then you can remove the symlink named @aolney/jupyterlab-metadata-html-extension within that folder.

Packaging the extension

See RELEASE

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file aolney_jupyterlab_metadata_html_extension-0.1.1.tar.gz.

File metadata

File hashes

Hashes for aolney_jupyterlab_metadata_html_extension-0.1.1.tar.gz
Algorithm Hash digest
SHA256 ee29fbbf09b0dbcc93f7e4dccfdafa910d1394302c4c20eb79e5a7bec16861ad
MD5 4223686f57f45ee5847ea2d260376b58
BLAKE2b-256 6bb31d2634f18ca8dbdac99c37a6e3926bd8830ac41cdb82b7b0f33636de9bdd

See more details on using hashes here.

File details

Details for the file aolney_jupyterlab_metadata_html_extension-0.1.1-py3-none-any.whl.

File metadata

File hashes

Hashes for aolney_jupyterlab_metadata_html_extension-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 a3fce16c0af3f3485f1dd717ba343a07b9efb763c5cf34d52354208e56c473d3
MD5 9238bdb558e5557ecdc80efac73ccb63
BLAKE2b-256 8a279a728864063ce35a4564a2e8a015fcd33e42ba96f4a0bf93f292955adc51

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page