chore: add deployment config option to append custom csp directives (#15596)

Allows adding custom static CSP directives to Coder. Niche use case but
makes this easier then creating a reverse proxy that has to replace the
header. We want to preserve our directives, so having an append option
is preferred to a "replace" option via a reverse proxy.


Closes https://github.com/coder/coder/issues/15118
This commit is contained in:
Steven Masley
2024-11-21 11:53:53 -06:00
committed by GitHub
parent f38f746f5d
commit 5b7fa78676
13 changed files with 140 additions and 39 deletions
+7
View File
@@ -294,6 +294,13 @@ backed by Tailscale and WireGuard.
+ 1`. Use special value 'disable' to turn off STUN completely.
NETWORKING / HTTP OPTIONS:
--additional-csp-policy string-array, $CODER_ADDITIONAL_CSP_POLICY
Coder configures a Content Security Policy (CSP) to protect against
XSS attacks. This setting allows you to add additional CSP directives,
which can open the attack surface of the deployment. Format matches
the CSP directive format, e.g. --additional-csp-policy="script-src
https://example.com".
--disable-password-auth bool, $CODER_DISABLE_PASSWORD_AUTH
Disable password authentication. This is recommended for security
purposes in production deployments that rely on an identity provider.
+6
View File
@@ -16,6 +16,12 @@ networking:
# HTTP bind address of the server. Unset to disable the HTTP endpoint.
# (default: 127.0.0.1:3000, type: string)
httpAddress: 127.0.0.1:3000
# Coder configures a Content Security Policy (CSP) to protect against XSS attacks.
# This setting allows you to add additional CSP directives, which can open the
# attack surface of the deployment. Format matches the CSP directive format, e.g.
# --additional-csp-policy="script-src https://example.com".
# (default: <unset>, type: string-array)
additionalCSPPolicy: []
# The maximum lifetime duration users can specify when creating an API token.
# (default: 876600h0m0s, type: duration)
maxTokenLifetime: 876600h0m0s