Conformance statement
Security Statement
Scope
This statement describes the security properties of the Smart.Industrial components and modules as shipped in the smart-industrial package and the Smart.Blazor.Industrial NuGet package: what the code does on the network, what it stores, how it treats the data it is given, how it behaves under a Content Security Policy, and what it depends on. It is written for the security review that precedes the use of a third-party library in an industrial control system, and it lists what the library does not provide as clearly as what it does.
The components are client-side user interface code. They run in the browser of the operator station, render the data the application gives them, and raise events when the operator acts. They contain no server, no protocol stack, no authentication and no authorization. Those are properties of the system the components are part of.
This page covers:
- Network activity
- Local storage
- Input handling and injection
- Content Security Policy
- Supply chain and dependencies
- Authentication, authorization and records
- Resource limits
- IEC 62443
- Reporting a vulnerability
Network activity
The components make no network requests that the application has not configured, and the framework under them makes none: the license is checked on the device. The places in the package that can use the network are listed below. Each goes only where the application points it, and none is active until the application sets the property or calls the function named.
| Code | Destination | When | What is sent |
|---|---|---|---|
| Smart.Industrial.Connect adapters | The WebSocket, SSE or HTTP endpoints the application configures | When the application opens a session | The subscriptions and writes the application makes. The manual adapter uses the application's own client and opens nothing. |
| Smart.Industrial.ai | The provider or endpoint the application configures | Only when the application has called configure(); unconfigured, every function rejects | The reduced statistics described in the AI Analysis guide, not the raw data. |
| smart-site-map | The tile server in its tiles property, or the picture in its background property | Only when the application sets one of them | Image requests for map tiles or the picture. The tile server receives the zoom level and tile coordinates of the view; a plant without Internet access can name its own tile server. |
| The data adapter of the Smart UI Table, which the alarm grid and the sequence editor are built on | A URL the application gives as a data source | Only when the application gives a table a remote data source; the alarm grid and the sequence editor are given their records as arrays | The request the application configures. |
The license is checked on the device: the key the page sets (Smart.License, the smart-license attribute of the body or an element's unlockKey) is compared with the key of the release, and nothing is sent anywhere. In evaluation mode (no valid key) the first component that checks the key shows two links for about ten seconds, one to the license page and one to the GitHub repository, and writes an evaluation notice to the console; neither loads remote content.
Air-gapped stations. A station without Internet access runs licensed exactly as one with it: nothing in the package needs a connection, at start or later.
There is no telemetry, usage reporting, crash reporting or update check in the package.
Local storage
The components store nothing about the process, the operator or the application unless the application asks for it. Nothing about the license is stored: the key is read from the page each time. No cookies are set. Components that offer state persistence (for example the mimic's layout() or the audit trail's export) return data to the application and do not store it themselves. The one exception is inherited from the Smart UI Table under the alarm grid and the sequence editor: with autoSaveState set, or when saveState() is called, it writes its view state (the parts named in stateSettings: columns, expanded, filtered, grouped, selected and sorted rows) to localStorage under smartTable followed by the element's id. autoSaveState is off by default.
Input handling and injection
Every value a component displays is rendered as text. Labels, tags, messages, reasons, user names, notes and every other string that arrives through a property or a record is HTML-escaped before it is placed in the DOM, and values that select a state, a severity or a mode are checked against the list of allowed values and fall back to a default when they are not in it. A test in the product's test suite sets every string property and every text field of every array and object property of all 54 components to an HTML payload and fails if any of it is rendered as markup or executes.
Two hooks accept markup from the application by design, and only from the application:
- MimicSymbol.symbolTemplate: a function the application supplies to draw a symbol that is not in the built-in set. Its return value is inserted as SVG. It must not be built from plant data without escaping.
- Terminal.write() with ansiColors enabled interprets ANSI SGR colour codes. The text itself is escaped; the codes only select a colour class.
The Smart UI framework contains one use of eval: the optional props attribute, which lets a page reference a JavaScript variable by name from markup. The Industrial components and demos do not use it, and under a Content Security Policy without 'unsafe-eval' it fails safely. No component builds code from strings.
Content Security Policy
The components run under a Content Security Policy with the following directives. Nothing in the package needs inline scripts or 'unsafe-eval'.
| Directive | Requirement | Reason |
|---|---|---|
| script-src | 'self' (or the origin the package is served from) | The package is loaded as scripts or ES modules from your own origin. No inline scripts and no external scripts. |
| style-src | 'self' 'unsafe-inline' | The framework injects style elements for themes and scoped styles, and a few components write style attributes for computed values (the stack light segment colours, the strip chart and trend pen swatches, the state timeline segment positions, the anomaly heatmap legend). A policy without 'unsafe-inline' for styles renders the components without those values. |
| connect-src | 'self' plus your data endpoints | The sessions the application opens through Connect, the AI provider or endpoint when one is configured, and a table data source given as a URL. Nothing else in the package connects anywhere. |
| img-src, font-src | 'self', plus the tile server or picture given to a site map | The symbols are inline SVG and the icon font, smart-icons.woff2, is in the package (source/styles/font/, and source/components/font/ for the shadow-DOM builds) and is served from your origin. |
| frame-ancestors | As required by the application | The components do not use frames. |
Supply chain and dependencies
- No runtime dependencies. The smart-industrial package declares no dependencies. React and Angular are optional peer dependencies used only by the wrappers under react/ and angular/. The NuGet package depends on Microsoft.AspNetCore.Components, Microsoft.AspNetCore.Components.Web, Microsoft.CSharp and Newtonsoft.Json, in the versions that match each target framework. The NuGet audit that runs when the package is built reports no known vulnerability in the referenced versions or their dependency graph.
- Software bill of materials. The package includes sbom.cdx.json, a CycloneDX 1.5 document listing the package and its (empty) dependency set, for inclusion in an application's SBOM.
- Reproducible contents. Every file in the package is produced by the build from the sources in the repository. The package check run before publishing verifies that every file in the built folder is in the tarball and that the bundle, the wrappers and the NuGet package load and render.
- Source. The scripts in the package (the bundle, the modules under source/modules/ and the shadow-DOM builds under source/components/) are minified, and no source maps are included.
- Versions. Version numbers follow the Smart UI release and are never reused; a published version is never changed in place.
Authentication, authorization and records
The components do not authenticate users and do not decide who may do what. The E-Signature component collects a user ID and a password and raises the signRequest event; the application verifies the credentials and calls accept() or reject(). The password is passed in the event and the field is cleared when the event is raised; the component never stores or transmits it. Failed attempts are counted and the panel locks after maxAttempts; the same limit has to be enforced on the server. Every operator action in the other components (a setpoint, an acknowledgement, a command, a bypass, a value set on an input control) is an event that the application authorizes and performs.
The audit trail module produces hash-chained, time-stamped entries and the audit trail component verifies a chain and reports where it breaks. This is tamper evidence for a copy of the trail in the browser. The server-side copy, its protection and its retention are the application's. The 21 CFR Part 11 statement lists the division clause by clause.
In Blazor Server applications, the event handlers run on the server and the client sends only the event data over the SignalR circuit. In Blazor WebAssembly they run in the browser. In both cases the authorization decision belongs to the application code that handles the event.
Resource limits
Components that receive a continuous stream of data hold it in bounded buffers, so a fast or runaway data source cannot exhaust the browser's memory through the component: the strip chart and the scope hold their samples in ring buffers of historyLength samples (per channel on the scope), the terminal keeps at most maxLines lines and removes the oldest, the spectrum holds the latest block and its averages, the trend drops the oldest records beyond historyLength (except those inside the window on screen), the anomaly heatmap drops samples older than its time window, and the audit trail viewer renders at most maxRows rows. The strip chart, scope, spectrum and trend draw at most once per animation frame, so the rate of incoming samples does not multiply the rate of rendering. A gap is drawn as a gap rather than converted to zero.
IEC 62443
IEC 62443 addresses the security of industrial automation and control systems. A user interface library cannot be certified against it; the system integrator's zone and conduit design, the product supplier's development process and the component requirements of IEC 62443-4-2 all apply to the system and the product the components are built into. The table lists, for each foundational requirement of IEC 62443-4-2, what the library contributes and what remains with the application.
| Foundational requirement | Library | Application |
|---|---|---|
| FR 1 Identification and authentication control | The E-Signature collects credentials and passes them to the application; it verifies nothing and stores nothing. | Identity verification, session management, lockout enforcement on the server. |
| FR 2 Use control | The components that act on the plant (faceplate, device control, selector switch, state machine, jog panel, momentary button, the alarm acknowledgements, the permissive's bypass) raise a request event and do not change their own value; on the faceplate, the device control and the state machine, interactive off means no request is raised. The input controls (knob, bar graph, bit field, thermometer, panel meter, numeric keypad) take the operator's value themselves and raise change. Interlocks and permissives are displayed, not enforced. | Authorization of every request and every change before it is written to the plant. |
| FR 3 System integrity | Input validation: all data is rendered as text and enumerated values are checked (CR 3.5). The audit trail's hash chain detects an altered copy (CR 3.4 tamper evidence for the client-side copy). | Integrity of the served files (subresource integrity, signed deployments), of the server and of the control system. |
| FR 4 Data confidentiality | No process or user data is stored or transmitted by the components, and nothing about the license is stored. | Transport encryption for the data sessions, protection of data at rest. |
| FR 5 Restricted data flow | The components open no connections of their own; the Connect sessions and the AI module, both configured by the application, are the only outbound flows, and both can be blocked by policy. | Zone and conduit design; allowing or blocking the outbound flows listed under Network activity. |
| FR 6 Timely response to events | The audit trail, alarm grid and sequence-of-events display keep and show the records they are given with their timestamps and resolution intact. | Event collection, storage, monitoring and response. |
| FR 7 Resource availability | Bounded buffers and batched rendering, as listed under Resource limits. | Backup, recovery and the availability of the servers and the network. |
Reporting a vulnerability
Report a suspected vulnerability to support@jqwidgets.com with "Security" in the subject, including the package name and version, the component, and a page or description that reproduces the issue. Please do not post it in the public forum. The report is acknowledged, the issue is assessed, and a fix is released in the next Smart UI release, or earlier for a confirmed high-severity issue; reporters are informed when the fix is available. The current release is supported; fixes are not backported to earlier major versions. The same policy is shipped in the package as SECURITY.md.