about summary refs log tree commit diff
path: root/config/initializers/content_security_policy.rb
diff options
context:
space:
mode:
authorThibaut Girka <thib@sitedethib.com>2018-08-28 21:41:03 +0200
committerThibG <thib@sitedethib.com>2018-08-28 22:10:40 +0200
commitc4b34791733de5b396a726aeff3f16d349e56c7e (patch)
tree8d53e42a1b6a40ecf0d82aedffc508d49d84a508 /config/initializers/content_security_policy.rb
parent4a9e3f80e837796daf3661bd4fbcd8929c6841f9 (diff)
Fix CSP with S3/SWIFT hosts
Diffstat (limited to 'config/initializers/content_security_policy.rb')
-rw-r--r--config/initializers/content_security_policy.rb15
1 files changed, 13 insertions, 2 deletions
diff --git a/config/initializers/content_security_policy.rb b/config/initializers/content_security_policy.rb
index 1308f0fd1..6d7666c48 100644
--- a/config/initializers/content_security_policy.rb
+++ b/config/initializers/content_security_policy.rb
@@ -4,6 +4,16 @@
 
 if Rails.env.production?
   assets_host = Rails.configuration.action_controller.asset_host || "https://#{ENV['WEB_DOMAIN'] || ENV['LOCAL_DOMAIN']}"
+  data_hosts = [assets_host]
+
+  if ENV['S3_ENABLED'] == 'true'
+    attachments_host = ENV['S3_ALIAS_HOST'] || ENV['S3_CLOUDFRONT_HOST'] || ENV['S3_HOSTNAME'] || "s3-#{ENV['S3_REGION'] || 'us-east-1'}.amazonaws.com"
+  elsif ENV['SWIFT_ENABLED'] == 'true'
+    attachments_host = ENV['SWIFT_OBJECT_URL']
+  else
+    attachments_host = nil
+  end
+  data_hosts << attachments_host unless attachments_host.nil?
 
   Rails.application.config.content_security_policy do |p|
     p.base_uri        :none
@@ -13,9 +23,10 @@ if Rails.env.production?
     p.font_src        :self, assets_host
     p.img_src         :self, :https, :data, :blob
     p.style_src       :self, :unsafe_inline, assets_host
-    p.media_src       :self, :data, assets_host
+    p.media_src       :self, :data, *data_hosts
     p.frame_src       :self, :https
-    p.connect_src     :self, :blob, assets_host, Rails.configuration.x.streaming_api_base_url
+    p.worker_src      :self, assets_host
+    p.connect_src     :self, :blob, Rails.configuration.x.streaming_api_base_url, *data_hosts
   end
 end