From d93f093005373831b0ffec1ce9a1ca2f85bf50a5 Mon Sep 17 00:00:00 2001 From: davelopez <46503462+davelopez@users.noreply.github.com> Date: Wed, 15 Oct 2025 10:22:07 +0200 Subject: [PATCH] Rebuild config --- doc/source/admin/galaxy_options.rst | 20 ++++++++++++++++++++ lib/galaxy/config/sample/galaxy.yml.sample | 12 ++++++++++++ 2 files changed, 32 insertions(+) diff --git a/doc/source/admin/galaxy_options.rst b/doc/source/admin/galaxy_options.rst index 8f922c5526c..91bca499024 100644 --- a/doc/source/admin/galaxy_options.rst +++ b/doc/source/admin/galaxy_options.rst @@ -5638,6 +5638,26 @@ :Type: str +~~~~~~~~~~~~~~~~~~~~~~~~~~~ +``url_headers_config_file`` +~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +:Description: + Configuration file for URL request headers allow-list with URL + pattern matching. This file defines which HTTP headers are allowed + in URL fetch requests based on URL patterns, and whether they + should be treated as sensitive (encrypted in the vault) or not. If + no allow-list is specified, no headers will be allowed in URL + requests. This provides fine-grained security control over what + headers can be sent when Galaxy fetches external URLs on behalf of + users, allowing different headers for different target domains or + services. + The value of this option will be resolved with respect to + . +:Default: ``url_headers_conf.yml`` +:Type: str + + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ``display_builtin_converters`` ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ diff --git a/lib/galaxy/config/sample/galaxy.yml.sample b/lib/galaxy/config/sample/galaxy.yml.sample index df7c57d9a77..a6b611ca089 100644 --- a/lib/galaxy/config/sample/galaxy.yml.sample +++ b/lib/galaxy/config/sample/galaxy.yml.sample @@ -3048,6 +3048,18 @@ galaxy: # . #vault_config_file: vault_conf.yml + # Configuration file for URL request headers allow-list with URL + # pattern matching. This file defines which HTTP headers are allowed + # in URL fetch requests based on URL patterns, and whether they should + # be treated as sensitive (encrypted in the vault) or not. If no + # allow-list is specified, no headers will be allowed in URL requests. + # This provides fine-grained security control over what headers can be + # sent when Galaxy fetches external URLs on behalf of users, allowing + # different headers for different target domains or services. + # The value of this option will be resolved with respect to + # . + #url_headers_config_file: url_headers_conf.yml + # Display built-in converters in the tool panel. #display_builtin_converters: true