From 3e20ea13d8a686a58ade84fe4ab97793faa8ea39 Mon Sep 17 00:00:00 2001 From: Pierre de La Morinerie Date: Tue, 8 Feb 2022 22:20:08 +0100 Subject: [PATCH] =?UTF-8?q?Revert=20"Utilisation=20des=20variables=20d'env?= =?UTF-8?q?ironnement=20lors=20de=20la=20d=C3=A9claration=20des=20Content?= =?UTF-8?q?=20Security=20Policies"?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../initializers/content_security_policy.rb | 31 +++++-------------- config/initializers/{02_urls.rb => urls.rb} | 4 +-- 2 files changed, 9 insertions(+), 26 deletions(-) rename config/initializers/{02_urls.rb => urls.rb} (93%) diff --git a/config/initializers/content_security_policy.rb b/config/initializers/content_security_policy.rb index 73d7177a4..17aa4aef0 100644 --- a/config/initializers/content_security_policy.rb +++ b/config/initializers/content_security_policy.rb @@ -4,45 +4,30 @@ # For further information see the following documentation # https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy +# rubocop:disable DS/ApplicationName Rails.application.config.content_security_policy do |policy| # Whitelist image - images_whitelist = ["*.openstreetmap.org", "*.cloud.ovh.net", "*"] - images_whitelist << URI(FOG_OPENSTACK_URL).host if FOG_OPENSTACK_URL.present? - images_whitelist << URI(MATOMO_IFRAME_URL).host if MATOMO_IFRAME_URL.present? - policy.img_src(:self, :data, :blob, *images_whitelist) - + policy.img_src :self, "*.openstreetmap.org", "static.demarches-simplifiees.fr", "*.cloud.ovh.net", "stats.data.gouv.fr", "*", :data, :blob # Whitelist JS: nous, sendinblue et matomo # miniprofiler et nous avons quelques boutons inline :( - scripts_whitelist = ["*.sendinblue.com", "*.crisp.chat", "crisp.chat", "*.sibautomation.com", "sibautomation.com", "cdn.jsdelivr.net", "maxcdn.bootstrapcdn.com", "code.jquery.com"] - scripts_whitelist << URI(MATOMO_IFRAME_URL).host if MATOMO_IFRAME_URL.present? - policy.script_src(:self, :unsafe_eval, :unsafe_inline, :blob, *scripts_whitelist) - + policy.script_src :self, "stats.data.gouv.fr", "*.sendinblue.com", "*.crisp.chat", "crisp.chat", "*.sibautomation.com", "sibautomation.com", 'cdn.jsdelivr.net', 'maxcdn.bootstrapcdn.com', 'code.jquery.com', :unsafe_eval, :unsafe_inline, :blob # Pour les CSS, on a beaucoup de style inline et quelques balises