mirror of
https://github.com/wassname/talk.git
synced 2026-07-29 11:28:24 +08:00
disable by default
This commit is contained in:
@@ -48,10 +48,9 @@ const CONFIG = {
|
||||
// request all of the records. Otherwise, minimum limits of 0 are enforced.
|
||||
ALLOW_NO_LIMIT_QUERIES: process.env.TALK_ALLOW_NO_LIMIT_QUERIES === 'TRUE',
|
||||
|
||||
// ONLY_REPORT_CSP_VIOLATIONS disables strict CSP enforcement, and only
|
||||
// reports CSP violations instead of blocking them.
|
||||
ONLY_REPORT_CSP_VIOLATIONS:
|
||||
process.env.TALK_ONLY_REPORT_CSP_VIOLATIONS === 'TRUE',
|
||||
// ENABLE_STRICT_CSP enables strict CSP enforcement, and will enforce as well
|
||||
// as report CSP violations.
|
||||
ENABLE_STRICT_CSP: process.env.TALK_ENABLE_STRICT_CSP === 'TRUE',
|
||||
|
||||
// LOGGING_LEVEL specifies the logging level used by the bunyan logger.
|
||||
LOGGING_LEVEL: ['fatal', 'error', 'warn', 'info', 'debug', 'trace'].includes(
|
||||
|
||||
@@ -497,12 +497,13 @@ tracing of GraphQL requests.
|
||||
|
||||
**Note: Apollo Engine is a premium service, charges may apply.**
|
||||
|
||||
## TALK_ONLY_REPORT_CSP_VIOLATIONS
|
||||
## TALK_ENABLE_STRICT_CSP
|
||||
|
||||
Setting this to `TRUE` will enable the [report only](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP#Testing_your_policy)
|
||||
mode of the Content Security Policy. The policy is not enforced, but any
|
||||
violations are reported to a provided URI. If you are encountering issues with
|
||||
resources not loading, try experimenting with this parameter. (Default `FALSE`)
|
||||
Setting this to `TRUE` will enforce the [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP)
|
||||
(or CSP) policy. By default, this configuration is set to
|
||||
[report only](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP#Testing_your_policy)
|
||||
where the policy is not enforced, but any violations are reported to a provided
|
||||
URI. (Default `FALSE`)
|
||||
|
||||
## ALLOW_NO_LIMIT_QUERIES
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
const helmet = require('helmet');
|
||||
const { WEBSOCKET_LIVE_URI, ONLY_REPORT_CSP_VIOLATIONS } = require('../config');
|
||||
const { WEBSOCKET_LIVE_URI, ENABLE_STRICT_CSP } = require('../config');
|
||||
const { BASE_PATH, BASE_URL, STATIC_URL } = require('../url');
|
||||
const { URL } = require('url');
|
||||
|
||||
@@ -47,5 +47,5 @@ module.exports = helmet.contentSecurityPolicy({
|
||||
},
|
||||
browserSniff: false,
|
||||
// Allow the configuration to disable strict enforcement of CSP.
|
||||
reportOnly: ONLY_REPORT_CSP_VIOLATIONS,
|
||||
reportOnly: !ENABLE_STRICT_CSP,
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user