Spiegel von
https://github.com/dani-garcia/vaultwarden.git
synchronisiert 2024-11-22 05:10:29 +01:00
Reformat CSP header for readability
Dieser Commit ist enthalten in:
Ursprung
1e32db8c41
Commit
4283a49e0b
1 geänderte Dateien mit 20 neuen und 6 gelöschten Zeilen
26
src/util.rs
26
src/util.rs
|
@ -63,16 +63,30 @@ impl Fairing for AppHeaders {
|
||||||
// app.simplelogin.io, app.anonaddy.com, api.fastmail.com
|
// app.simplelogin.io, app.anonaddy.com, api.fastmail.com
|
||||||
let csp = format!(
|
let csp = format!(
|
||||||
"default-src 'self'; \
|
"default-src 'self'; \
|
||||||
|
object-src 'self' blob:; \
|
||||||
script-src 'self'{script_src}; \
|
script-src 'self'{script_src}; \
|
||||||
style-src 'self' 'unsafe-inline'; \
|
style-src 'self' 'unsafe-inline'; \
|
||||||
img-src 'self' data: https://haveibeenpwned.com/ https://www.gravatar.com {icon_service_csp}; \
|
|
||||||
child-src 'self' https://*.duosecurity.com https://*.duofederal.com; \
|
child-src 'self' https://*.duosecurity.com https://*.duofederal.com; \
|
||||||
frame-src 'self' https://*.duosecurity.com https://*.duofederal.com; \
|
frame-src 'self' https://*.duosecurity.com https://*.duofederal.com; \
|
||||||
connect-src 'self' https://api.pwnedpasswords.com/range/ https://2fa.directory/api/ https://app.simplelogin.io/api/ https://app.anonaddy.com/api/ https://api.fastmail.com/; \
|
frame-ancestors 'self' \
|
||||||
object-src 'self' blob:; \
|
chrome-extension://nngceckbapebfimnlniiiahkandclblb \
|
||||||
frame-ancestors 'self' chrome-extension://nngceckbapebfimnlniiiahkandclblb chrome-extension://jbkfoedolllekgbhcbcoahefnbanhhlh moz-extension://* {allowed_iframe_ancestors};",
|
chrome-extension://jbkfoedolllekgbhcbcoahefnbanhhlh \
|
||||||
icon_service_csp=CONFIG._icon_service_csp(),
|
moz-extension://* \
|
||||||
allowed_iframe_ancestors=CONFIG.allowed_iframe_ancestors()
|
{allowed_iframe_ancestors}; \
|
||||||
|
img-src 'self' data: \
|
||||||
|
https://haveibeenpwned.com/ \
|
||||||
|
https://www.gravatar.com \
|
||||||
|
{icon_service_csp}; \
|
||||||
|
connect-src 'self' \
|
||||||
|
https://api.pwnedpasswords.com/range/ \
|
||||||
|
https://2fa.directory/api/ \
|
||||||
|
https://app.simplelogin.io/api/ \
|
||||||
|
https://app.anonaddy.com/api/ \
|
||||||
|
https://api.fastmail.com/ \
|
||||||
|
;\
|
||||||
|
",
|
||||||
|
icon_service_csp = CONFIG._icon_service_csp(),
|
||||||
|
allowed_iframe_ancestors = CONFIG.allowed_iframe_ancestors()
|
||||||
);
|
);
|
||||||
res.set_raw_header("Content-Security-Policy", csp);
|
res.set_raw_header("Content-Security-Policy", csp);
|
||||||
res.set_raw_header("X-Frame-Options", "SAMEORIGIN");
|
res.set_raw_header("X-Frame-Options", "SAMEORIGIN");
|
||||||
|
|
Laden …
In neuem Issue referenzieren