Merge pull request #10139 from fschade/csp-conf-auto-loading

enhancement: Load CSP configuration file if it exists
This commit is contained in:
Florian Schade
2024-09-24 12:45:01 +02:00
committed by GitHub
2 changed files with 18 additions and 0 deletions
@@ -0,0 +1,8 @@
Enhancement: Load CSP configuration file if it exists
The Content Security Policy (CSP) configuration file is now loaded by default if it exists.
The configuration file looked for should be located at `$OCIS_BASE_DATA_PATH/proxy/csp.yaml`.
If the file does not exist, the default CSP configuration is used.
https://github.com/owncloud/ocis/pull/10139
https://github.com/owncloud/ocis/issues/10021
@@ -1,7 +1,9 @@
package defaults
import (
"os"
"path"
"path/filepath"
"strings"
"time"
@@ -332,6 +334,14 @@ func Sanitize(cfg *config.Config) {
if cfg.HTTP.Root != "/" {
cfg.HTTP.Root = strings.TrimSuffix(cfg.HTTP.Root, "/")
}
// if the CSP config file path is not set, we check if the default file exists and set it if it does
if cfg.CSPConfigFileLocation == "" {
defaultCSPConfigFilePath := filepath.Join(defaults.BaseDataPath(), "proxy", "csp.yaml")
if _, err := os.Stat(defaultCSPConfigFilePath); err == nil {
cfg.CSPConfigFileLocation = defaultCSPConfigFilePath
}
}
}
func mergePolicies(policies []config.Policy, additionalPolicies []config.Policy) []config.Policy {