mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add csp headers for embedded apps (#18374)
I modified the proxy host cache we already had and were using for websocket csp headers to also include the wildcard app host, then used those for frame-src policies. I did not add frame-ancestors, since if I understand correctly, those would go on the app, and this middleware does not come into play there. Maybe we will want to add it on workspace apps like we do with cors, if we find apps are setting it to `none` or something. Closes https://github.com/coder/internal/issues/684
This commit is contained in:
+20
-7
@@ -76,6 +76,7 @@ import (
|
||||
"github.com/coder/coder/v2/coderd/portsharing"
|
||||
"github.com/coder/coder/v2/coderd/prometheusmetrics"
|
||||
"github.com/coder/coder/v2/coderd/provisionerdserver"
|
||||
"github.com/coder/coder/v2/coderd/proxyhealth"
|
||||
"github.com/coder/coder/v2/coderd/rbac"
|
||||
"github.com/coder/coder/v2/coderd/rbac/policy"
|
||||
"github.com/coder/coder/v2/coderd/rbac/rolestore"
|
||||
@@ -85,6 +86,7 @@ import (
|
||||
"github.com/coder/coder/v2/coderd/updatecheck"
|
||||
"github.com/coder/coder/v2/coderd/util/slice"
|
||||
"github.com/coder/coder/v2/coderd/workspaceapps"
|
||||
"github.com/coder/coder/v2/coderd/workspaceapps/appurl"
|
||||
"github.com/coder/coder/v2/coderd/workspacestats"
|
||||
"github.com/coder/coder/v2/codersdk"
|
||||
"github.com/coder/coder/v2/codersdk/healthsdk"
|
||||
@@ -1534,16 +1536,27 @@ func New(options *Options) *API {
|
||||
// browsers, so these don't make sense on api routes.
|
||||
cspMW := httpmw.CSPHeaders(
|
||||
api.Experiments,
|
||||
options.Telemetry.Enabled(), func() []string {
|
||||
options.Telemetry.Enabled(), func() []*proxyhealth.ProxyHost {
|
||||
if api.DeploymentValues.Dangerous.AllowAllCors {
|
||||
// In this mode, allow all external requests
|
||||
return []string{"*"}
|
||||
// In this mode, allow all external requests.
|
||||
return []*proxyhealth.ProxyHost{
|
||||
{
|
||||
Host: "*",
|
||||
AppHost: "*",
|
||||
},
|
||||
}
|
||||
}
|
||||
// Always add the primary, since the app host may be on a sub-domain.
|
||||
proxies := []*proxyhealth.ProxyHost{
|
||||
{
|
||||
Host: api.AccessURL.Host,
|
||||
AppHost: appurl.ConvertAppHostForCSP(api.AccessURL.Host, api.AppHostname),
|
||||
},
|
||||
}
|
||||
if f := api.WorkspaceProxyHostsFn.Load(); f != nil {
|
||||
return (*f)()
|
||||
proxies = append(proxies, (*f)()...)
|
||||
}
|
||||
// By default we do not add extra websocket connections to the CSP
|
||||
return []string{}
|
||||
return proxies
|
||||
}, additionalCSPHeaders)
|
||||
|
||||
// Static file handler must be wrapped with HSTS handler if the
|
||||
@@ -1582,7 +1595,7 @@ type API struct {
|
||||
AppearanceFetcher atomic.Pointer[appearance.Fetcher]
|
||||
// WorkspaceProxyHostsFn returns the hosts of healthy workspace proxies
|
||||
// for header reasons.
|
||||
WorkspaceProxyHostsFn atomic.Pointer[func() []string]
|
||||
WorkspaceProxyHostsFn atomic.Pointer[func() []*proxyhealth.ProxyHost]
|
||||
// TemplateScheduleStore is a pointer to an atomic pointer because this is
|
||||
// passed to another struct, and we want them all to be the same reference.
|
||||
TemplateScheduleStore *atomic.Pointer[schedule.TemplateScheduleStore]
|
||||
|
||||
Reference in New Issue
Block a user