mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: add deployment config option to append custom csp directives (#15596)
Allows adding custom static CSP directives to Coder. Niche use case but makes this easier then creating a reverse proxy that has to replace the header. We want to preserve our directives, so having an append option is preferred to a "replace" option via a reverse proxy. Closes https://github.com/coder/coder/issues/15118
This commit is contained in:
+7
@@ -294,6 +294,13 @@ backed by Tailscale and WireGuard.
|
||||
+ 1`. Use special value 'disable' to turn off STUN completely.
|
||||
|
||||
NETWORKING / HTTP OPTIONS:
|
||||
--additional-csp-policy string-array, $CODER_ADDITIONAL_CSP_POLICY
|
||||
Coder configures a Content Security Policy (CSP) to protect against
|
||||
XSS attacks. This setting allows you to add additional CSP directives,
|
||||
which can open the attack surface of the deployment. Format matches
|
||||
the CSP directive format, e.g. --additional-csp-policy="script-src
|
||||
https://example.com".
|
||||
|
||||
--disable-password-auth bool, $CODER_DISABLE_PASSWORD_AUTH
|
||||
Disable password authentication. This is recommended for security
|
||||
purposes in production deployments that rely on an identity provider.
|
||||
|
||||
Reference in New Issue
Block a user