Welcome to mirror list, hosted at ThFree Co, Russian Federation.

gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
Diffstat (limited to 'app/controllers/concerns/web_ide_csp.rb')
-rw-r--r--app/controllers/concerns/web_ide_csp.rb34
1 files changed, 18 insertions, 16 deletions
diff --git a/app/controllers/concerns/web_ide_csp.rb b/app/controllers/concerns/web_ide_csp.rb
index c2d66abb538..0327020a0c2 100644
--- a/app/controllers/concerns/web_ide_csp.rb
+++ b/app/controllers/concerns/web_ide_csp.rb
@@ -5,25 +5,27 @@ module WebIdeCSP
included do
before_action :include_web_ide_csp
+ end
- # We want to include frames from `/assets/webpack` of the request's host to
- # support URL flexibility with the Web IDE.
- # https://gitlab.com/gitlab-org/gitlab/-/merge_requests/118875
- def include_web_ide_csp
- return if request.content_security_policy.directives.blank?
+ # We want to include frames from `/assets/webpack` of the request's host to
+ # support URL flexibility with the Web IDE.
+ # https://gitlab.com/gitlab-org/gitlab/-/merge_requests/118875
+ def include_web_ide_csp
+ return if request.content_security_policy.directives.blank?
- base_uri = URI(request.url)
- base_uri.path = ::Gitlab.config.gitlab.relative_url_root || '/'
- # `.path +=` handles combining `x/` and `/foo`
- base_uri.path += '/assets/webpack/'
- webpack_url = base_uri.to_s
+ base_uri = URI(request.url)
+ base_uri.path = ::Gitlab.config.gitlab.relative_url_root || '/'
+ # `.path +=` handles combining `x/` and `/foo`
+ base_uri.path += '/assets/webpack/'
+ webpack_url = base_uri.to_s
- default_src = Array(request.content_security_policy.directives['default-src'] || [])
- request.content_security_policy.directives['frame-src'] ||= default_src
- request.content_security_policy.directives['frame-src'].concat([webpack_url, 'https://*.vscode-cdn.net/'])
+ default_src = Array(request.content_security_policy.directives['default-src'] || [])
+ request.content_security_policy.directives['frame-src'] ||= default_src
+ request.content_security_policy.directives['frame-src'].concat([webpack_url, 'https://*.vscode-cdn.net/'])
- request.content_security_policy.directives['worker-src'] ||= default_src
- request.content_security_policy.directives['worker-src'].concat([webpack_url])
- end
+ request.content_security_policy.directives['worker-src'] ||= default_src
+ request.content_security_policy.directives['worker-src'].concat([webpack_url])
end
end
+
+WebIdeCSP.prepend_mod_with('WebIdeCSP')