-
Notifications
You must be signed in to change notification settings - Fork 1.8k
/
Copy pathcsp.ts
42 lines (38 loc) · 1.37 KB
/
csp.ts
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
/**
* Teleport
* Copyright (C) 2023 Gravitational, Inc.
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>.
*/
export function getConnectCsp(development: boolean) {
// feedbackAddress needs to be kept in sync with the same property in staticConfig.ts.
const feedbackAddress = development
? 'https://kcwm2is93l.execute-api.us-west-2.amazonaws.com/prod'
: 'https://usage.teleport.dev';
let csp = `
default-src 'self';
connect-src 'self' ${feedbackAddress};
style-src 'self' 'unsafe-inline';
img-src 'self' data: blob:;
object-src 'none';
font-src 'self' data:;
`
.replaceAll('\n', ' ')
.trim();
if (development) {
// Required to make source maps work in dev mode.
csp += " script-src 'self' 'unsafe-eval' 'unsafe-inline';";
}
return csp;
}