Skip to content

Commit 7a18f1f

Browse files
committed
chore(csp): remove redundant img-src entries superseded by https scheme
1 parent a3905af commit 7a18f1f

1 file changed

Lines changed: 2 additions & 16 deletions

File tree

  • apps/sim/lib/core/security

apps/sim/lib/core/security/csp.ts

Lines changed: 2 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -131,20 +131,7 @@ export const buildTimeCSPDirectives: CSPDirectives = {
131131
'script-src': [...STATIC_SCRIPT_SRC],
132132
'style-src': ["'self'", "'unsafe-inline'", 'https://fonts.googleapis.com'],
133133

134-
'img-src': [
135-
...STATIC_IMG_SRC,
136-
...(env.S3_BUCKET_NAME && env.AWS_REGION
137-
? [`https://${env.S3_BUCKET_NAME}.s3.${env.AWS_REGION}.amazonaws.com`]
138-
: []),
139-
...(env.S3_KB_BUCKET_NAME && env.AWS_REGION
140-
? [`https://${env.S3_KB_BUCKET_NAME}.s3.${env.AWS_REGION}.amazonaws.com`]
141-
: []),
142-
...(env.S3_CHAT_BUCKET_NAME && env.AWS_REGION
143-
? [`https://${env.S3_CHAT_BUCKET_NAME}.s3.${env.AWS_REGION}.amazonaws.com`]
144-
: []),
145-
...getHostnameFromUrl(env.NEXT_PUBLIC_BRAND_LOGO_URL),
146-
...getHostnameFromUrl(env.NEXT_PUBLIC_BRAND_FAVICON_URL),
147-
],
134+
'img-src': [...STATIC_IMG_SRC],
148135

149136
'media-src': ["'self'", 'blob:'],
150137
'worker-src': ["'self'", 'blob:'],
@@ -200,14 +187,13 @@ export function generateRuntimeCSP(): string {
200187
const ollamaUrl = getEnv('OLLAMA_URL') || (isDev ? DEFAULT_OLLAMA_URL : '')
201188

202189
const brandLogoDomains = getHostnameFromUrl(getEnv('NEXT_PUBLIC_BRAND_LOGO_URL'))
203-
const brandFaviconDomains = getHostnameFromUrl(getEnv('NEXT_PUBLIC_BRAND_FAVICON_URL'))
204190
const privacyDomains = getHostnameFromUrl(getEnv('NEXT_PUBLIC_PRIVACY_URL'))
205191
const termsDomains = getHostnameFromUrl(getEnv('NEXT_PUBLIC_TERMS_URL'))
206192

207193
const runtimeDirectives: CSPDirectives = {
208194
...buildTimeCSPDirectives,
209195

210-
'img-src': [...STATIC_IMG_SRC, ...brandLogoDomains, ...brandFaviconDomains],
196+
'img-src': [...STATIC_IMG_SRC],
211197

212198
'connect-src': [
213199
...STATIC_CONNECT_SRC,

0 commit comments

Comments
 (0)