Skip to content

Commit 50665f8

Browse files
Set default CSP domains
1 parent de6c1cc commit 50665f8

2 files changed

Lines changed: 5 additions & 2 deletions

File tree

chart/templates/configmap-nginx.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ data:
3232
{{- if .Values.nginx.securityHeaders.enabled }}
3333
add_header X-Content-Type-Options "{{ .Values.nginx.securityHeaders.xContentTypeOptions }}" always;
3434
add_header X-Frame-Options "{{ .Values.nginx.securityHeaders.xFrameOptions }}" always;
35-
add_header Content-Security-Policy "{{ .Values.nginx.securityHeaders.contentSecurityPolicy }}" always;
35+
add_header Content-Security-Policy "{{ .Values.nginx.securityHeaders.contentSecurityPolicy }}{{- range .Values.nginx.securityHeaders.extraCspDomains }} {{ . }}{{- end }};" always;
3636
add_header Permissions-Policy "{{ .Values.nginx.securityHeaders.permissionsPolicy }}" always;
3737
add_header Referrer-Policy "{{ .Values.nginx.securityHeaders.referrerPolicy }}" always;
3838
{{- else }}

chart/values.yaml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -538,7 +538,10 @@ nginx:
538538
securityHeaders:
539539
enabled: true
540540
xContentTypeOptions: "nosniff"
541-
contentSecurityPolicy: "default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob:;"
541+
contentSecurityPolicy: "default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: https://login.openops.com https://assets.frontegg.com https://fonts.cdnfonts.com https://fonts.googleapis.com https://fonts.gstatic.com https://api.github.com https://app.openops.com https://cdn.jsdelivr.net"
542+
# Additional domains to append to the CSP default-src directive
543+
extraCspDomains: []
544+
# - https://example.com
542545
permissionsPolicy: "geolocation=(), microphone=(), camera=()"
543546
referrerPolicy: "strict-origin-when-cross-origin"
544547
# Rate limiting - ENABLED BY DEFAULT for security

0 commit comments

Comments
 (0)