feat(media-proxy): sign attachment URLs and gate origins (#2830)

This commit is contained in:
Hampus
2026-09-18 15:57:32 +02:00
committed by GitHub
parent 025c01ab13
commit 522cf08e61
108 changed files with 10148 additions and 441 deletions
+30
View File
@@ -198,6 +198,36 @@ FLUXER_VAPID_PRIVATE_KEY=CHANGE_ME
#FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS=https://chat.example.com
#FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS=http://chat.example.com:19080
# Two optional media policies, both off unless you turn them on. Nothing below is
# needed for a working instance, and an upgrade never adds any of it.
#
# The first limits which web origins may read media through CORS. A request with
# no Origin header is always served, so direct links, image tags and native
# clients keep working. The allowlist defaults to the public origin above, which
# is where this instance serves its web app. The hosted web client and the
# desktop app run on https://web.fluxer.app, so add that origin, as in the second
# allowlist line, if people use them with this instance.
#
# The second makes an attachment read need a signed URL, which stops a copied
# link working forever elsewhere. Turning it on takes two settings: a secret, and
# the mode. Generate the secret with openssl rand -base64 32. It is a comma
# separated list, the first entry signs and every entry verifies. To rotate, add
# the new secret second and run docker compose up -d, then move it first and run
# again. Remove the old secret no sooner than a day after that, because an
# ordinary URL it signed stays valid for up to a day. A data package URL inside a
# harvest export never expires, so removing a secret ends every data package URL
# it signed and those exports have to be rebuilt.
#
# Each mode is off, report or enforce on its own. Set a mode to report first to
# log what enforce would refuse while refusing nothing. media-proxy reads these
# at container start, so apply a change with docker compose up -d media-proxy.
# docker compose restart media-proxy keeps the old environment.
#FLUXER_MEDIA_PROXY_CORS_MODE=enforce
#FLUXER_MEDIA_PROXY_CORS_ALLOWED_ORIGINS=https://chat.example.com
#FLUXER_MEDIA_PROXY_CORS_ALLOWED_ORIGINS=https://chat.example.com,https://web.fluxer.app
#FLUXER_MEDIA_PROXY_ATTACHMENT_URL_SECRETS_BASE64=
#FLUXER_MEDIA_PROXY_ATTACHMENT_SIGNATURE_MODE=enforce
# Extra Content-Security-Policy sources, appended to the built-in ones. Set these
# only when a browser must reach an origin the defaults do not cover, such as a
# voice server hosted on a domain other than FLUXER_DOMAIN. Separate several