Thibaut Girka
06bcab6e99
Fix CSP when PAPERCLIP_ROOT_URL is set to a different host
2019-05-04 10:55:56 +02:00
Thibaut Girka
5d24d50987
Fix CSP when dealing with S3 hosts
2019-05-04 00:47:51 +02:00
Rey Tucker
56890834ab
Remove form_action from CSP
...
This trips an issue when trying to authenticate through to
third-party sites, e.g. bridge.joinmastodon.org:
Refused to send form data to 'https://bridge.joinmastodon.org/ '
because it violates the following Content Security Policy
directive: "form-action 'self'".
Thread: https://vulpine.club/@digifox/101230933751352042
2018-12-14 08:02:06 +01:00
Thibaut Girka
b7ef203fd6
Tighten CSP a bit
2018-11-12 15:43:02 +01:00
Thibaut Girka
46259a36d0
Merge branch 'master' into glitch-soc/merge-upstream
...
Conflicts:
- .github/ISSUE_TEMPLATE/bug_report.md
Took our version.
- CONTRIBUTING.md
Updated the embedded copy of upstream's version.
- README.md
Took our version.
- app/policies/status_policy.rb
Not a real conflict, took code from both.
- app/views/layouts/embedded.html.haml
Added upstream's changes (dns-prefetch) and fixed
`%body.embed`
- app/views/settings/preferences/show.html.haml
Reverted some of upstream changes, as we have a
page dedicated for flavours and skins.
- config/initializers/content_security_policy.rb
Kept our version of the CSP.
- config/initializers/doorkeeper.rb
Not a real conflict, took code from both.
2018-10-22 17:51:38 +02:00
ThibG
f8e9555e73
Add manifest_src to CSP, add blob to connect_src ( #8967 )
2018-10-12 19:07:30 +02:00
Eugen Rochko
0dbb3a8786
Fix CSP headers blocking media and development environment ( #8962 )
...
Regression from #8957
2018-10-12 01:43:09 +02:00
ThibG
51c53e709f
Set Content-Security-Policy rules through RoR's config ( #8957 )
...
* Set CSP rules in RoR's configuration
* Override CSP setting in the embed controller to allow frames
2018-10-11 20:35:46 +02:00
Rey Tucker
121747b190
Add manifest_src to CSP
...
Fixes manifest.json not being loaded because of CSP violation
h/t https://vulpine.club/@binary/100662852252438648
2018-09-03 22:37:54 +02:00
Thibaut Girka
0a841048fa
Fix CSP with S3/SWIFT hosts
2018-08-28 22:10:40 +02:00
Thibaut Girka
2f78bd1b42
Adjust CSP to fix image resizing
2018-08-28 16:58:55 +02:00
Thibaut Girka
36a96b33d9
Only apply CSP in production mode
2018-08-23 22:58:40 +02:00
Thibaut Girka
91c50b0d4b
Tighten CSP while allowing CDN hosts
2018-08-23 22:58:40 +02:00
Thibaut Girka
563a09d81a
Move CSP headers to the appropriate Rails configuration
...
Also drop dev-static.glitch.social reference.
2018-08-22 20:39:33 +02:00
Yamagishi Kazutoshi
9761b940ac
Upgrade Rails to version 5.2.0 ( #5898 )
2018-04-12 14:45:17 +02:00