0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-04 10:39:43 +08:00
discourse/lib/content_security_policy/default.rb
David Taylor fc0d388c24
UX: Do not include upgrade-insecure-requests in report-only CSP (#41414)
This directive is not supported in report-only CSP, and causes confusing
errors to be logged to the browser console. Omit it in report-only mode.
2026-07-03 09:56:08 +01:00

60 lines
1.8 KiB
Ruby
Vendored

# frozen_string_literal: true
require "content_security_policy"
class ContentSecurityPolicy
class Default
attr_reader :directives
def initialize(report_only: false)
@directives =
{}.tap do |directives|
# `upgrade-insecure-requests` is ignored in a report-only policy, and
# browsers log a console warning when it is present there, so only
# emit it for the enforced policy.
directives[:upgrade_insecure_requests] = [] if SiteSetting.force_https && !report_only
directives[:base_uri] = [:self]
directives[:object_src] = [:none]
directives[:script_src] = script_src
directives[:worker_src] = worker_src
directives[:frame_ancestors] = frame_ancestors if restrict_embed?
directives[:manifest_src] = ["'self'"]
directives[:report_uri] = [report_uri] if report_uri.present?
end
end
private
def script_src
sources = %w['strict-dynamic' 'wasm-unsafe-eval']
sources << "'report-sample'" if report_uri.present?
sources
end
def report_uri
SiteSetting.content_security_policy_report_uri.presence
end
def worker_src
[:self, "blob:", *worker_asset_host]
end
def worker_asset_host
if GlobalSetting.use_s3? && GlobalSetting.s3_cdn_url.present?
s3_cdn = GlobalSetting.s3_asset_cdn_url.presence || GlobalSetting.s3_cdn_url
["#{s3_cdn}/assets/"]
elsif GlobalSetting.cdn_url.present?
["#{GlobalSetting.cdn_url}#{Discourse.base_path}/assets/"]
else
[]
end
end
def frame_ancestors
["'self'", *EmbeddableHost.pluck(:host).map { |host| "https://#{host}" }]
end
def restrict_embed?
SiteSetting.content_security_policy_frame_ancestors && !SiteSetting.embed_any_origin
end
end
end