CORS and CSP headers (#1286)

* do in-app compression only for CLI

* CORS and CSP headers

* lint

* add --debug to targets

* lint

* fix botched merge with master
This commit is contained in:
Bruce Martin
2020-03-24 08:05:37 -07:00
committed by GitHub
parent d196cbc8f6
commit 752b9e4ab3
7 changed files with 29 additions and 9 deletions
+5 -3
View File
@@ -4,7 +4,6 @@ import logging
from flask import Flask, redirect, current_app, make_response, render_template, abort
from flask import Blueprint, request, send_from_directory
from flask_cors import CORS
from flask_restful import Api, Resource
from http import HTTPStatus
@@ -204,10 +203,9 @@ class Server:
def __init__(self, matrix_data_cache_manager, annotations, app_config):
self.app = Flask(__name__, static_folder="../common/web/static")
self._before_adding_routes(app_config)
self.app.json_encoder = Float32JSONEncoder
CORS(self.app, supports_credentials=True)
# enable session data
self.app.permanent_session_lifetime = datetime.timedelta(days=50 * 365)
@@ -238,3 +236,7 @@ class Server:
self.app.matrix_data_cache_manager = matrix_data_cache_manager
self.app.annotations = annotations
self.app.app_config = app_config
def _before_adding_routes(self, app_config):
""" will be called before routes are added. Subclass protocol """
pass