From 838687a3ae47494fa7d0f2ab9b3e66f601e56552 Mon Sep 17 00:00:00 2001 From: Wyatt Johnson Date: Mon, 1 Oct 2018 16:58:14 -0600 Subject: [PATCH] fix: added support for static uri in CSP header for social callback --- services/passport.js | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/services/passport.js b/services/passport.js index 4b96d2352..d7749e615 100644 --- a/services/passport.js +++ b/services/passport.js @@ -97,6 +97,11 @@ const HandleGenerateCredentials = (req, res, next) => (err, user) => { res.json({ user, token }); }; +const generateAuthPopupCallbackCSP = req => + req.locals.STATIC_URL && req.locals.BASE_URL !== req.locals.STATIC_URL + ? `default-src 'self' ${req.locals.STATIC_URL};` + : "default-src 'self';"; + /** * Returns the response to the login attempt via a popup callback with some JS. */ @@ -106,7 +111,7 @@ const HandleAuthPopupCallback = (req, res, next) => (err, user) => { res.header('Pragma', 'no-cache'); // Ensure the only scripts that can run here are those on the Talk domain. - res.header('Content-Security-Policy', "default-src 'self';"); + res.header('Content-Security-Policy', generateAuthPopupCallbackCSP(req)); // Attach static locals to the response locals object. attachStaticLocals(res.locals);