Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replace security_disable_frames with security_csp_frame_ancestors #721

Merged
merged 2 commits into from
Oct 30, 2020
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion ood-portal-generator/lib/ood_portal_generator/view.rb
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ def initialize(opts = {})
@maintenance_ip_whitelist = Array(opts.fetch(:maintenance_ip_whitelist, []))

# Security configuration
@security_disable_frames = opts.fetch(:security_disable_frames, true)
@security_csp_frame_ancestors = opts.fetch(:security_csp_frame_ancestors, "#{@protocol}#{@servername ? @servername : OodPortalGenerator.fqdn}")
@security_strict_transport = opts.fetch(:security_strict_transport, !@ssl.nil?)

# Portal authentication
Expand Down
10 changes: 6 additions & 4 deletions ood-portal-generator/share/ood_portal_example.yml
Original file line number Diff line number Diff line change
Expand Up @@ -80,11 +80,13 @@
# Default: [] (no IPs whitelisted)
#maintenance_ip_whitelist: []

# Set Header Content-Security-Policy to disallow OnDemand beind loaded in an iFrame.
# Set Header Content-Security-Policy frame-ancestors.
# Example:
# security_disable_frames: false
# Default: true
#security_disable_frames: true
# security_csp_frame_ancestors: https://ondemand.osc.edu
# Example to disable setting:
# security_csp_frame_ancestors: false
# Default: based on servername and ssl settings
#security_disable_frames:

# Set Header Strict-Transport-Security to help enforce SSL
# Example:
Expand Down
2 changes: 1 addition & 1 deletion ood-portal-generator/spec/fixtures/ood-portal.conf.default
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@
ErrorDocument 503 /public/maintenance/index.html
Header Set Cache-Control "max-age=0, no-store"

Header always set Content-Security-Policy "frame-ancestors none;"
Header always set Content-Security-Policy "frame-ancestors http://example.com;"

# Lua configuration
#
Expand Down
2 changes: 1 addition & 1 deletion ood-portal-generator/spec/fixtures/ood-portal.conf.dex
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@
ErrorDocument 503 /public/maintenance/index.html
Header Set Cache-Control "max-age=0, no-store"

Header always set Content-Security-Policy "frame-ancestors none;"
Header always set Content-Security-Policy "frame-ancestors http://example.com;"

# OIDC configuration
#
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@
ErrorDocument 503 /public/maintenance/index.html
Header Set Cache-Control "max-age=0, no-store"

Header always set Content-Security-Policy "frame-ancestors none;"
Header always set Content-Security-Policy "frame-ancestors https://example.com;"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"

SSLEngine On
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@
ErrorDocument 503 /public/maintenance/index.html
Header Set Cache-Control "max-age=0, no-store"

Header always set Content-Security-Policy "frame-ancestors none;"
Header always set Content-Security-Policy "frame-ancestors https://example.com;"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"

SSLEngine On
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@
ErrorDocument 503 /public/maintenance/index.html
Header Set Cache-Control "max-age=0, no-store"

Header always set Content-Security-Policy "frame-ancestors none;"
Header always set Content-Security-Policy "frame-ancestors http://example.com;"

# Lua configuration
#
Expand Down
2 changes: 1 addition & 1 deletion ood-portal-generator/spec/fixtures/ood-portal.conf.nomaint
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@
CustomLog "logs/access.log" combined


Header always set Content-Security-Policy "frame-ancestors none;"
Header always set Content-Security-Policy "frame-ancestors http://example.com;"

# Lua configuration
#
Expand Down
2 changes: 1 addition & 1 deletion ood-portal-generator/spec/fixtures/ood-portal.conf.oidc
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@
ErrorDocument 503 /public/maintenance/index.html
Header Set Cache-Control "max-age=0, no-store"

Header always set Content-Security-Policy "frame-ancestors none;"
Header always set Content-Security-Policy "frame-ancestors http://ondemand.example.com;"

# OIDC configuration
#
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@
ErrorDocument 503 /public/maintenance/index.html
Header Set Cache-Control "max-age=0, no-store"

Header always set Content-Security-Policy "frame-ancestors none;"
Header always set Content-Security-Policy "frame-ancestors https://ondemand.example.com;"
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"

SSLEngine On
Expand Down
2 changes: 1 addition & 1 deletion ood-portal-generator/spec/fixtures/sum.default
Original file line number Diff line number Diff line change
@@ -1 +1 @@
9be4a58d643ec6f97069520f9e378b7ac5f1b5b9c74979293cb1144c0928e267 /opt/rh/httpd24/root/etc/httpd/conf.d/ood-portal.conf
c8df0e79d2d670868b62ef4bdeed0a223c55c2e45efe80050dfae5c4324d24b5 /opt/rh/httpd24/root/etc/httpd/conf.d/ood-portal.conf
2 changes: 1 addition & 1 deletion ood-portal-generator/spec/update_ood_portal_spec.rb
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@

before(:each) do
allow(OodPortalGenerator).to receive(:apache_group).and_return('apache')
allow(OodPortalGenerator).to receive(:fqdn).and_return('example.com')
end

after(:each) do
Expand Down Expand Up @@ -119,7 +120,6 @@

context 'dex' do
before(:each) do
allow(OodPortalGenerator).to receive(:fqdn).and_return('example.com')
allow(OodPortalGenerator::Dex).to receive(:installed?).and_return(true)
allow_any_instance_of(OodPortalGenerator::Dex).to receive(:enabled?).and_return(true)
allow(OodPortalGenerator).to receive(:dex_user).and_return(user)
Expand Down
4 changes: 2 additions & 2 deletions ood-portal-generator/templates/ood-portal.conf.erb
Original file line number Diff line number Diff line change
Expand Up @@ -95,8 +95,8 @@ Listen <%= addr_port %>
Header Set Cache-Control "max-age=0, no-store"

<%- end -%>
<%- if @security_disable_frames -%>
Header always set Content-Security-Policy "frame-ancestors none;"
<%- if @security_csp_frame_ancestors -%>
Header always set Content-Security-Policy "frame-ancestors <%= @security_csp_frame_ancestors -%>;"
<%- end -%>
<%- if @security_strict_transport -%>
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
Expand Down