Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
C
canifa_note
Project
Project
Details
Activity
Releases
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Vũ Hoàng Anh
canifa_note
Commits
99d9cc91
Unverified
Commit
99d9cc91
authored
Dec 23, 2022
by
boojack
Committed by
GitHub
Dec 23, 2022
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
fix: set csp header only for resource (#836)
parent
119603da
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
1 addition
and
4 deletions
+1
-4
resource.go
server/resource.go
+1
-0
server.go
server/server.go
+0
-4
No files found.
server/resource.go
View file @
99d9cc91
...
...
@@ -265,6 +265,7 @@ func (s *Server) registerResourcePublicRoutes(g *echo.Group) {
c
.
Response
()
.
Writer
.
Header
()
.
Set
(
"Content-Type"
,
resource
.
Type
)
c
.
Response
()
.
Writer
.
WriteHeader
(
http
.
StatusOK
)
c
.
Response
()
.
Writer
.
Header
()
.
Set
(
echo
.
HeaderCacheControl
,
"max-age=31536000, immutable"
)
c
.
Response
()
.
Writer
.
Header
()
.
Set
(
echo
.
HeaderContentSecurityPolicy
,
"default-src 'self'"
)
if
_
,
err
:=
c
.
Response
()
.
Writer
.
Write
(
resource
.
Blob
);
err
!=
nil
{
return
echo
.
NewHTTPError
(
http
.
StatusInternalServerError
,
"Failed to write response"
)
.
SetInternal
(
err
)
}
...
...
server/server.go
View file @
99d9cc91
...
...
@@ -44,10 +44,6 @@ func NewServer(profile *profile.Profile) *Server {
Timeout
:
30
*
time
.
Second
,
}))
e
.
Use
(
middleware
.
SecureWithConfig
(
middleware
.
SecureConfig
{
ContentSecurityPolicy
:
"default-src 'self'"
,
}))
embedFrontend
(
e
)
// In dev mode, set the const secret key to make signin session persistence.
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment