* * @author Roeland Jago Douma * * @license GNU AGPL version 3 or any later version * * This program is free software: you can redistribute it and/or modify * it under the terms of the GNU Affero General Public License as * published by the Free Software Foundation, either version 3 of the * License, or (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU Affero General Public License for more details. * * You should have received a copy of the GNU Affero General Public License * along with this program. If not, see . * */ namespace OCA\Talk\Listener; use OCA\Talk\Config; use OCP\AppFramework\Http\ContentSecurityPolicy; use OCP\EventDispatcher\Event; use OCP\EventDispatcher\IEventListener; use OCP\Security\CSP\AddContentSecurityPolicyEvent; class CSPListener implements IEventListener { /** @var Config */ private $config; public function __construct(Config $config) { $this->config = $config; } public function handle(Event $event): void { if (!($event instanceof AddContentSecurityPolicyEvent)) { return; } $csp = new ContentSecurityPolicy(); $csp->addAllowedImageDomain('https://*.tile.openstreetmap.org'); foreach ($this->config->getAllServerUrlsForCSP() as $server) { $csp->addAllowedConnectDomain($server); } $event->addPolicy($csp); } }