chore: add deployment config option to append custom csp directives (#15596)

Allows adding custom static CSP directives to Coder. Niche use case but
makes this easier then creating a reverse proxy that has to replace the
header. We want to preserve our directives, so having an append option
is preferred to a "replace" option via a reverse proxy.


Closes https://github.com/coder/coder/issues/15118
This commit is contained in:
Steven Masley
2024-11-21 11:53:53 -06:00
committed by GitHub
parent f38f746f5d
commit 5b7fa78676
13 changed files with 140 additions and 39 deletions
+10
View File
@@ -829,6 +829,16 @@ Output Stackdriver compatible logs to a given file.
Allow administrators to enable Terraform debug output.
### --additional-csp-policy
| | |
| ----------- | ------------------------------------------------ |
| Type | <code>string-array</code> |
| Environment | <code>$CODER_ADDITIONAL_CSP_POLICY</code> |
| YAML | <code>networking.http.additionalCSPPolicy</code> |
Coder configures a Content Security Policy (CSP) to protect against XSS attacks. This setting allows you to add additional CSP directives, which can open the attack surface of the deployment. Format matches the CSP directive format, e.g. --additional-csp-policy="script-src https://example.com".
### --dangerous-allow-path-app-sharing
| | |