US09-01: Serve the Documentation Inside the Application (#107)
This commit was merged in pull request #107.
This commit is contained in:
@@ -57,9 +57,21 @@ LOOPBACK_HOSTS = frozenset({"127.0.0.1", "localhost", "::1", "[::1]"})
|
||||
# backup a careful operator takes first, and its retention (US07-07).
|
||||
MUTATION_EXEMPT_PATHS = frozenset({f"{API_PREFIX}/backups", f"{API_PREFIX}/backups/prune"})
|
||||
|
||||
# Applied to every response. No inline script/style is used by the frontend, so the
|
||||
# policy can stay strict; `frame-ancestors 'none'` and CORP keep other pages from
|
||||
# Applied to every response. `frame-ancestors 'none'` and CORP keep other pages from
|
||||
# embedding the app or its thumbnails.
|
||||
#
|
||||
# `script-src 'self'` is the boundary that matters and it is unchanged: no
|
||||
# `'unsafe-eval'`, no `'unsafe-inline'`, so nothing injected into the DOM can execute.
|
||||
# Whether the vendored diagram renderer needed `'unsafe-eval'` was measured rather
|
||||
# than assumed — mermaid's bundle contains no `eval(` and no `new Function`, and it
|
||||
# renders under this exact policy without a single script-src violation.
|
||||
#
|
||||
# `style-src` does gain `'unsafe-inline'` (US09-01): mermaid styles the SVG it builds
|
||||
# with an injected `<style>` element and `style=` attributes, and a diagram's CSS
|
||||
# cannot be hashed in advance. The concession is bounded by the directives around it
|
||||
# — with script execution still refused and `img-src`, `connect-src`, and `font-src`
|
||||
# all `'self'`, the CSS exfiltration channels stay closed and what is left is
|
||||
# defacement of a page its own operator is already looking at.
|
||||
DEFAULT_HEADERS = {
|
||||
"x-content-type-options": "nosniff",
|
||||
"x-frame-options": "DENY",
|
||||
@@ -67,8 +79,9 @@ DEFAULT_HEADERS = {
|
||||
"cross-origin-resource-policy": "same-origin",
|
||||
"cross-origin-opener-policy": "same-origin",
|
||||
"content-security-policy": (
|
||||
"default-src 'self'; img-src 'self' data:; style-src 'self'; script-src 'self'; "
|
||||
"connect-src 'self'; frame-ancestors 'none'; base-uri 'none'; form-action 'none'"
|
||||
"default-src 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline'; "
|
||||
"script-src 'self'; connect-src 'self'; font-src 'self'; "
|
||||
"frame-ancestors 'none'; base-uri 'none'; form-action 'none'"
|
||||
),
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user