Browse Source

Fix CSP when PAPERCLIP_ROOT_URL is set to a different host

closed-social-glitch-2
Thibaut Girka 5 years ago
committed by ThibG
parent
commit
2c2f649200
1 changed files with 8 additions and 0 deletions
  1. +8
    -0
      config/initializers/content_security_policy.rb

+ 8
- 0
config/initializers/content_security_policy.rb View File

@ -15,8 +15,16 @@ if Rails.env.production?
else
attachments_host = nil
end
data_hosts << attachments_host unless attachments_host.nil?
if ENV['PAPERCLIP_ROOT_URL']
url = Addressable::URI.parse(assets_host) + ENV['PAPERCLIP_ROOT_URL']
data_hosts << "https://#{url.host}"
end
data_hosts.uniq!
Rails.application.config.content_security_policy do |p|
p.base_uri :none
p.default_src :none

Loading…
Cancel
Save