mirror of
https://github.com/chanzuckerberg/cellxgene.git
synced 2026-09-29 18:58:11 +08:00
CSP content hashes (#1406)
* remove duplicate content-type header * plumbing to compute CSP content hashes * add logging of missing CSP hashes * convert sub-class init protocol to static * factor function * lint
This commit is contained in:
+6
-5
@@ -242,9 +242,14 @@ def get_api_resources(bp_api):
|
||||
|
||||
|
||||
class Server:
|
||||
@staticmethod
|
||||
def _before_adding_routes(app, app_config):
|
||||
""" will be called before routes are added, during __init__. Subclass protocol """
|
||||
pass
|
||||
|
||||
def __init__(self, app_config):
|
||||
self.app = Flask(__name__, static_folder="../common/web/static")
|
||||
self._before_adding_routes(app_config)
|
||||
self._before_adding_routes(self.app, app_config)
|
||||
self.app.json_encoder = Float32JSONEncoder
|
||||
if app_config.server__server_timing_headers:
|
||||
ServerTiming(self.app, force_debug=True)
|
||||
@@ -275,7 +280,3 @@ class Server:
|
||||
self.app.matrix_data_cache_manager = app_config.matrix_data_cache_manager
|
||||
self.app.annotations = app_config.user_annotations
|
||||
self.app.app_config = app_config
|
||||
|
||||
def _before_adding_routes(self, app_config):
|
||||
""" will be called before routes are added. Subclass protocol """
|
||||
pass
|
||||
|
||||
@@ -278,8 +278,9 @@ class CliLaunchServer(Server):
|
||||
def __init__(self, app_config):
|
||||
super().__init__(app_config)
|
||||
|
||||
def _before_adding_routes(self, app_config):
|
||||
self.app.config["COMPRESS_MIMETYPES"] = [
|
||||
@staticmethod
|
||||
def _before_adding_routes(app, app_config):
|
||||
app.config["COMPRESS_MIMETYPES"] = [
|
||||
"text/html",
|
||||
"text/css",
|
||||
"text/xml",
|
||||
@@ -287,9 +288,9 @@ class CliLaunchServer(Server):
|
||||
"application/javascript",
|
||||
"application/octet-stream",
|
||||
]
|
||||
Compress(self.app)
|
||||
Compress(app)
|
||||
if app_config.server__debug:
|
||||
CORS(self.app, supports_credentials=True)
|
||||
CORS(app, supports_credentials=True)
|
||||
|
||||
|
||||
@sort_options
|
||||
|
||||
@@ -30,4 +30,6 @@ def health_check(config):
|
||||
]
|
||||
health["status"] = "pass" if all(checks) else "fail"
|
||||
code = HTTPStatus.OK if health["status"] == "pass" else HTTPStatus.BAD_REQUEST
|
||||
return make_response(jsonify(health), code, {"Content-Type": "application/health+json"},)
|
||||
response = make_response(jsonify(health), code)
|
||||
response.headers["Content-Type"] = "application/health+json"
|
||||
return response
|
||||
|
||||
+33
-4
@@ -2,10 +2,10 @@
|
||||
|
||||
import sys
|
||||
import os
|
||||
from flask import json
|
||||
import logging
|
||||
from flask_talisman import Talisman
|
||||
import boto3
|
||||
import json
|
||||
|
||||
if os.path.isdir("/opt/python/log"):
|
||||
# This is the standard location where Amazon EC2 instances store the application logs.
|
||||
@@ -52,9 +52,38 @@ class WSGIServer(Server):
|
||||
def __init__(self, app_config):
|
||||
super().__init__(app_config)
|
||||
|
||||
def _before_adding_routes(self, app_config):
|
||||
csp = {"default-src": "'self' 'unsafe-inline' 'unsafe-eval'", "img-src": ["'self'", "data:"]}
|
||||
Talisman(self.app, force_https=app_config.server__force_https, content_security_policy=csp)
|
||||
@staticmethod
|
||||
def _before_adding_routes(app, app_config):
|
||||
script_hashes, style_hashes = WSGIServer.load_csp_hashes(app)
|
||||
csp = {
|
||||
"default-src": "'self'",
|
||||
"script-src": ["'unsafe-eval'", "'unsafe-inline'"] + script_hashes,
|
||||
"img-src": ["'self'", "data:"],
|
||||
"object-src": "'none'",
|
||||
"base-uri": "'none'",
|
||||
}
|
||||
if len(style_hashes) > 0:
|
||||
csp["style-src"] = style_hashes
|
||||
|
||||
Talisman(app, force_https=app_config.server__force_https, content_security_policy=csp)
|
||||
|
||||
@staticmethod
|
||||
def load_csp_hashes(app):
|
||||
csp_hashes = None
|
||||
try:
|
||||
with app.open_resource("../common/web/csp-hashes.json") as f:
|
||||
csp_hashes = json.load(f)
|
||||
except FileNotFoundError:
|
||||
pass
|
||||
if not isinstance(csp_hashes, dict):
|
||||
csp_hashes = {}
|
||||
script_hashes = [f"'{hash}'" for hash in csp_hashes.get("script-hashes", [])]
|
||||
style_hashes = [f"'{hash}'" for hash in csp_hashes.get("style-hashes", [])]
|
||||
|
||||
if len(script_hashes) == 0 or len(style_hashes) == 0:
|
||||
logging.error("Content security policy hashes are missing, falling back to unsafe-inline policy")
|
||||
|
||||
return (script_hashes, style_hashes)
|
||||
|
||||
|
||||
try:
|
||||
|
||||
Reference in New Issue
Block a user