mirror of
https://github.com/chanzuckerberg/cellxgene.git
synced 2026-09-30 14:08:11 +08:00
Fixes from frontend/backend url separation (#1829)
* Fixes from frontend/backend url separation This fixes the CORS and CSP headers. Also, in thie commit, I removed the cors_supports_credentials config parameter, which was recently introduced. Instead, the logic determines the need to use CORS headers if the web_page_url is set. #1778
This commit is contained in:
+18
-2
@@ -4,10 +4,11 @@ import sys
|
||||
import os
|
||||
import hashlib
|
||||
import base64
|
||||
from urllib.parse import urlparse
|
||||
from flask import json
|
||||
import logging
|
||||
from flask_talisman import Talisman
|
||||
|
||||
from flask_cors import CORS
|
||||
from server.common.aws_secret_utils import handle_config_from_secret
|
||||
from server.common.errors import SecretKeyRetrievalError
|
||||
|
||||
@@ -41,6 +42,14 @@ class WSGIServer(Server):
|
||||
def _before_adding_routes(app, app_config):
|
||||
script_hashes = WSGIServer.get_csp_hashes(app, app_config)
|
||||
server_config = app_config.server_config
|
||||
|
||||
# add the api_base_url to the connect_src csp header.
|
||||
extra_connect_src = []
|
||||
api_base_url = server_config.get_api_base_url()
|
||||
if api_base_url:
|
||||
parse_api_base_url = urlparse(api_base_url)
|
||||
extra_connect_src = [f"{parse_api_base_url.scheme}://{parse_api_base_url.netloc}"]
|
||||
|
||||
# This hash should be in sync with the script within
|
||||
# `client/configuration/webpack/obsoleteHTMLTemplate.html`
|
||||
|
||||
@@ -51,7 +60,7 @@ class WSGIServer(Server):
|
||||
obsolete_browser_script_hash = ["'sha256-/rmgOi/skq9MpiZxPv6lPb1PNSN+Uf4NaUHO/IjyfwM='"]
|
||||
csp = {
|
||||
"default-src": ["'self'"],
|
||||
"connect-src": ["'self'"],
|
||||
"connect-src": ["'self'"] + extra_connect_src,
|
||||
"script-src": ["'self'", "'unsafe-eval'"]
|
||||
+ obsolete_browser_script_hash + script_hashes,
|
||||
"style-src": ["'self'", "'unsafe-inline'"],
|
||||
@@ -70,6 +79,13 @@ class WSGIServer(Server):
|
||||
v = [v]
|
||||
csp[k] = csp.get(k, []) + v
|
||||
|
||||
# Add the web_base_url to the CORS header
|
||||
web_base_url = server_config.get_web_base_url()
|
||||
if web_base_url:
|
||||
web_base_url_parse = urlparse(web_base_url)
|
||||
allowed_origin = f"{web_base_url_parse.scheme}://{web_base_url_parse.netloc}"
|
||||
CORS(app, supports_credentials=True, origins=allowed_origin)
|
||||
|
||||
Talisman(
|
||||
app, force_https=server_config.app__force_https, frame_options="DENY", content_security_policy=csp,
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user