-
Type:
Bug
-
Resolution: Fixed
-
Affects Version/s: None
-
Component/s: Editor general
-
High
-
None
-
If there are custom help pages configured the URLs are now automatically allowed by CSP header rules.
-
None
-
Emptyshow more show less
problem
With TRANSLATE-5381 we increased security by introducing several HTTP header security features. This includes CSP rules, where all traffic started by the browser to different domains must be allowed.
In the config the administrators of an instance can set several URLs to be loaded by the application in the UI, these are:
runtimeOptions.editor.customPanel.url runtimeOptions.frontend.helpWindow.customeroverview.loaderUrl runtimeOptions.frontend.helpWindow.editor.loaderUrl runtimeOptions.frontend.helpWindow.instanttranslate.loaderUrl runtimeOptions.frontend.helpWindow.languageresource.loaderUrl runtimeOptions.frontend.helpWindow.preferences.loaderUrl runtimeOptions.frontend.helpWindow.project.loaderUrl runtimeOptions.frontend.helpWindow.taskoverview.loaderUrl runtimeOptions.frontend.helpWindow.termportal.loaderUrl
solution
This configs must be parsed on initial page load and the found servers must be added to the CSP rule automatically. Attention URL may contain a path only pointing to self - so no CSP is needed here.
- is caused by
-
TRANSLATE-5381 Add headers suggested by HTTP Observatory
- Done