URLs out of config must be added automatically to HTTP CSP rules

XMLWordPrintable

    • High
    • None
    • If there are custom help pages configured the URLs are now automatically allowed by CSP header rules.
    • None

      problem

      With TRANSLATE-5381 we increased security by introducing several HTTP header security features. This includes CSP rules, where all traffic started by the browser to different domains must be allowed. 

      In the config the administrators of an instance can set several URLs to be loaded by the application in the UI, these are: 

      runtimeOptions.editor.customPanel.url  runtimeOptions.frontend.helpWindow.customeroverview.loaderUrl
      runtimeOptions.frontend.helpWindow.editor.loaderUrl
      runtimeOptions.frontend.helpWindow.instanttranslate.loaderUrl
      runtimeOptions.frontend.helpWindow.languageresource.loaderUrl
      runtimeOptions.frontend.helpWindow.preferences.loaderUrl
      runtimeOptions.frontend.helpWindow.project.loaderUrl
      runtimeOptions.frontend.helpWindow.taskoverview.loaderUrl
      runtimeOptions.frontend.helpWindow.termportal.loaderUrl

      solution

      This configs must be parsed on initial page load and the found servers must be added to the CSP rule automatically. Attention URL may contain a path only pointing to self - so no CSP is needed here.

            Assignee:
            Leon Kiz
            Reporter:
            Thomas Lauria
            None
            None
            Thomas Lauria
            Stephan Bergmann, Sylvia Schumacher
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved:
              None
              None