Refactor build and CSP headers for Safari compat (#1442)

* add unsafe-inline directive to style-src

* debugging - turn on csp reporting

* revert reporting only csp

* do not inline JS and CSS in build

* enable HTTPs only when in production mode

* remove debug printf

* fix clean target

* revert force_https removal
This commit is contained in:
Bruce Martin
2020-05-04 12:47:35 -07:00
committed by GitHub
parent 6cccc41c0f
commit f42f5151a6
7 changed files with 1340 additions and 42 deletions
+8 -7
View File
@@ -60,18 +60,17 @@ class WSGIServer(Server):
script_hashes, style_hashes = WSGIServer.get_csp_hashes(app, app_config)
csp = {
"default-src": ["'self'"],
"script-src": ["'unsafe-eval'", "'unsafe-inline'"] + script_hashes,
"script-src": ["'self'", "'unsafe-eval'", "'unsafe-inline'"] + script_hashes,
"style-src": ["'self'", "'unsafe-inline'"] + style_hashes,
"img-src": ["'self'", "data:"],
"object-src": ["'none'"],
"base-uri": ["'none'"],
"upgrade-insecure-requests": [""],
"frame-ancestors": ["'none'"],
"require-trusted-types-for": ["'script'"],
}
if len(style_hashes) > 0:
csp["style-src"] = style_hashes
if app_config.server__inline_scripts:
csp["script-src"].append("'strict-dynamic'")
if not app.debug:
csp["upgrade-insecure-requests"] = ""
if app_config.server__csp_directives:
for k, v in app_config.server__csp_directives.items():
@@ -79,7 +78,9 @@ class WSGIServer(Server):
v = [v]
csp[k] = csp.get(k, []) + v
Talisman(app, force_https=app_config.server__force_https, frame_options="DENY", content_security_policy=csp)
Talisman(
app, force_https=app_config.server__force_https, frame_options="DENY", content_security_policy=csp,
)
@staticmethod
def load_static_csp_hashes(app):