mirror of
https://github.com/fluxerapp/fluxer
synced 2026-10-07 19:22:14 +09:00
fix(app-proxy): make the SPA shell identical for every visitor (#3112)
This commit is contained in:
Generated
+1
@@ -2040,6 +2040,7 @@ dependencies = [
|
||||
"reqwest",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sha2 0.11.0",
|
||||
"tokio",
|
||||
"tokio-util",
|
||||
"tower",
|
||||
|
||||
@@ -23,9 +23,9 @@
|
||||
<meta name="display" content="standalone">
|
||||
<link rel="license" href="/assets/fonts-NOTICE.txt">
|
||||
<!--{{FLUXER_BOOTSTRAP}}-->
|
||||
<script nonce="{{CSP_NONCE_PLACEHOLDER}}">(function(){try{var loc=window.location;if(loc.pathname==='/'){var target='/channels/@me';if(loc.search)target+=loc.search;if(loc.hash)target+=loc.hash;loc.replace(target);}}catch(e){}})();</script>
|
||||
<script nonce="{{CSP_NONCE_PLACEHOLDER}}">(function(){try{var t=localStorage.getItem('theme');if(t){document.documentElement.classList.add('theme-'+t)}}catch{}})()</script>
|
||||
<script nonce="{{CSP_NONCE_PLACEHOLDER}}">(function(){try{if(typeof WebSocket!=='function')return;if(window.location.pathname.indexOf('/migrate/')===0)return;var t=localStorage.getItem('token');if(!t||t==='undefined'||t==='null')return;var b=window.__FLUXER_BOOTSTRAP__;var g=b&&b.instance&&b.instance.endpoints&&b.instance.endpoints.gateway;if(!g)return;var u=new URL(g);u.searchParams.set('v','1');u.searchParams.set('encoding','json');u.searchParams.set('compress','zstd-stream');u.searchParams.set('stream','1');var url=u.toString();var ws=new WebSocket(url);ws.binaryType='arraybuffer';var s={open:false,url:url,messages:[],startedAt:Date.now()};ws.onopen=function(){s.open=true};ws.onmessage=function(e){s.messages.push(e)};ws.onclose=ws.onerror=function(){window.__FLUXER_FAST_CONNECT__=null};window.__FLUXER_FAST_CONNECT__={ws:ws,state:s};setTimeout(function(){var h=window.__FLUXER_FAST_CONNECT__;if(h&&h.ws===ws){window.__FLUXER_FAST_CONNECT__=null;try{ws.close(1000,'Fast connect unclaimed')}catch(e){}}},30000)}catch(e){}})()</script>
|
||||
<script>(function(){try{var loc=window.location;if(loc.pathname==='/'){var target='/channels/@me';if(loc.search)target+=loc.search;if(loc.hash)target+=loc.hash;loc.replace(target);}}catch(e){}})();</script>
|
||||
<script>(function(){try{var t=localStorage.getItem('theme');if(t){document.documentElement.classList.add('theme-'+t)}}catch{}})()</script>
|
||||
<script>(function(){try{if(typeof WebSocket!=='function')return;if(window.location.pathname.indexOf('/migrate/')===0)return;var t=localStorage.getItem('token');if(!t||t==='undefined'||t==='null')return;var b=window.__FLUXER_BOOTSTRAP__;var g=b&&b.instance&&b.instance.endpoints&&b.instance.endpoints.gateway;if(!g)return;var u=new URL(g);u.searchParams.set('v','1');u.searchParams.set('encoding','json');u.searchParams.set('compress','zstd-stream');u.searchParams.set('stream','1');var url=u.toString();var ws=new WebSocket(url);ws.binaryType='arraybuffer';var s={open:false,url:url,messages:[],startedAt:Date.now()};ws.onopen=function(){s.open=true};ws.onmessage=function(e){s.messages.push(e)};ws.onclose=ws.onerror=function(){window.__FLUXER_FAST_CONNECT__=null};window.__FLUXER_FAST_CONNECT__={ws:ws,state:s};setTimeout(function(){var h=window.__FLUXER_FAST_CONNECT__;if(h&&h.ws===ws){window.__FLUXER_FAST_CONNECT__=null;try{ws.close(1000,'Fast connect unclaimed')}catch(e){}}},30000)}catch(e){}})()</script>
|
||||
</head>
|
||||
<body>
|
||||
<div id="root"></div>
|
||||
|
||||
@@ -160,7 +160,7 @@ async function bootstrapApp(): Promise<void> {
|
||||
loadLazyModule(() => import('@app/features/auth/state/AccountManager')),
|
||||
loadLazyModule(() => import('@app/features/channel/state/ChannelDisplayName')),
|
||||
loadLazyModule(() => import('@app/features/channel/state/ChannelFrecency')),
|
||||
loadLazyModule(() => import('@app/features/app/state/GeoIP')),
|
||||
loadLazyModule(() => import('@app/features/app/state/GeoIP')).then(({default: GeoIP}) => GeoIP.load()),
|
||||
loadLazyModule(() => import('@app/features/input/state/InputKeybind')),
|
||||
loadLazyModule(() => import('@app/features/auth/state/NewDeviceMonitoring')),
|
||||
loadLazyModule(() => import('@app/features/ui/state/Notification')),
|
||||
|
||||
Vendored
+1
-5
@@ -2,10 +2,7 @@
|
||||
|
||||
import MediaEngineFacade from '@app/features/voice/engine/MediaEngineFacade';
|
||||
import type {ElectronAPI} from '@app/features/platform/types/Electron';
|
||||
import type {
|
||||
GeolocationResponse,
|
||||
InstanceDiscoveryResponse,
|
||||
} from '@fluxer/instance_bootstrap/src/Types';
|
||||
import type {InstanceDiscoveryResponse} from '@fluxer/instance_bootstrap/src/Types';
|
||||
import {Buffer} from 'buffer';
|
||||
|
||||
type MediaEngineInstance = typeof MediaEngineFacade;
|
||||
@@ -31,7 +28,6 @@ interface FluxerBootstrapGlobal {
|
||||
bootstrapApiPublicEndpoint?: string;
|
||||
};
|
||||
instance: InstanceDiscoveryResponse;
|
||||
geoip: GeolocationResponse;
|
||||
}
|
||||
|
||||
declare global {
|
||||
|
||||
@@ -1,38 +1,95 @@
|
||||
// SPDX-License-Identifier: AGPL-3.0-or-later
|
||||
|
||||
import type {GeoEntry, GeolocationResponse} from '@fluxer/instance_bootstrap/src/Types';
|
||||
import {Logger} from '@app/features/platform/utils/AppLogger';
|
||||
import ageGeos from '@fluxer/constants/src/AgeGeos.json';
|
||||
import type {GeoEntry} from '@fluxer/instance_bootstrap/src/Types';
|
||||
import {GeolocationResponse} from '@fluxer/schema/src/domains/geolocation/GeolocationSchemas';
|
||||
import {makeAutoObservable, runInAction} from 'mobx';
|
||||
|
||||
const GEOIP_PATH = '/_geoip';
|
||||
const GEOIP_ATTEMPTS = 3;
|
||||
const GEOIP_ATTEMPT_TIMEOUT_MS = 2000;
|
||||
const GEOIP_RETRY_DELAY_MS = 200;
|
||||
|
||||
const logger = new Logger('GeoIP');
|
||||
|
||||
interface ConnectionGeoCoordinates {
|
||||
latitude: string | null;
|
||||
longitude: string | null;
|
||||
}
|
||||
|
||||
function getInlinedGeoip(): GeolocationResponse {
|
||||
const bootstrap = typeof window !== 'undefined' ? window.__FLUXER_BOOTSTRAP__ : undefined;
|
||||
if (!bootstrap) {
|
||||
throw new Error('window.__FLUXER_BOOTSTRAP__ is missing — app must be served by fluxer_app_proxy');
|
||||
}
|
||||
return bootstrap.geoip;
|
||||
const UNRESOLVED_GEOIP: GeolocationResponse = {
|
||||
countryCode: null,
|
||||
regionCode: null,
|
||||
latitude: null,
|
||||
longitude: null,
|
||||
ageRestrictedGeos: ageGeos.ageRestrictedGeos,
|
||||
ageBlockedGeos: ageGeos.ageBlockedGeos,
|
||||
};
|
||||
|
||||
function wait(ms: number): Promise<void> {
|
||||
return new Promise((resolve) => setTimeout(resolve, ms));
|
||||
}
|
||||
|
||||
async function fetchGeoipOnce(): Promise<GeolocationResponse> {
|
||||
const controller = new AbortController();
|
||||
const timer = setTimeout(() => controller.abort(), GEOIP_ATTEMPT_TIMEOUT_MS);
|
||||
try {
|
||||
const response = await fetch(GEOIP_PATH, {
|
||||
cache: 'no-store',
|
||||
credentials: 'omit',
|
||||
headers: {Accept: 'application/json'},
|
||||
signal: controller.signal,
|
||||
});
|
||||
if (!response.ok) {
|
||||
throw new Error(`GeoIP lookup failed with status ${response.status}`);
|
||||
}
|
||||
return GeolocationResponse.parse(await response.json());
|
||||
} finally {
|
||||
clearTimeout(timer);
|
||||
}
|
||||
}
|
||||
|
||||
async function fetchGeoip(): Promise<GeolocationResponse> {
|
||||
for (let attempt = 1; ; attempt++) {
|
||||
try {
|
||||
return await fetchGeoipOnce();
|
||||
} catch (error) {
|
||||
if (attempt >= GEOIP_ATTEMPTS) {
|
||||
logger.warn('GeoIP lookup failed, continuing without a location:', error);
|
||||
return UNRESOLVED_GEOIP;
|
||||
}
|
||||
await wait(GEOIP_RETRY_DELAY_MS * attempt);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
let loading: Promise<void> | null = null;
|
||||
|
||||
class GeoIP {
|
||||
countryCode: string | null;
|
||||
regionCode: string | null;
|
||||
latitude: string | null;
|
||||
longitude: string | null;
|
||||
ageRestrictedGeos: ReadonlyArray<GeoEntry>;
|
||||
ageBlockedGeos: ReadonlyArray<GeoEntry>;
|
||||
countryCode: string | null = UNRESOLVED_GEOIP.countryCode;
|
||||
regionCode: string | null = UNRESOLVED_GEOIP.regionCode;
|
||||
latitude: string | null = UNRESOLVED_GEOIP.latitude;
|
||||
longitude: string | null = UNRESOLVED_GEOIP.longitude;
|
||||
ageRestrictedGeos: ReadonlyArray<GeoEntry> = UNRESOLVED_GEOIP.ageRestrictedGeos;
|
||||
ageBlockedGeos: ReadonlyArray<GeoEntry> = UNRESOLVED_GEOIP.ageBlockedGeos;
|
||||
|
||||
constructor() {
|
||||
const data = getInlinedGeoip();
|
||||
makeAutoObservable(this, {}, {autoBind: true});
|
||||
}
|
||||
|
||||
load(): Promise<void> {
|
||||
loading ??= fetchGeoip().then((data) => {
|
||||
runInAction(() => {
|
||||
this.countryCode = data.countryCode;
|
||||
this.regionCode = data.regionCode;
|
||||
this.latitude = data.latitude;
|
||||
this.longitude = data.longitude;
|
||||
this.ageRestrictedGeos = data.ageRestrictedGeos;
|
||||
this.ageBlockedGeos = data.ageBlockedGeos;
|
||||
makeAutoObservable(this, {}, {autoBind: true});
|
||||
});
|
||||
});
|
||||
return loading;
|
||||
}
|
||||
|
||||
applyConnectionFallbackCoordinates(data: ConnectionGeoCoordinates): void {
|
||||
|
||||
@@ -19,14 +19,14 @@ const UNRENDERED_INDEX_TEMPLATE = [
|
||||
'<!doctype html><html lang="en"><head>',
|
||||
'<link rel="preconnect" href="{{STATIC_CDN_ENDPOINT}}">',
|
||||
'<link rel="apple-touch-icon" href="{{STATIC_CDN_ENDPOINT}}/web/apple-touch-icon.png">',
|
||||
'<script nonce="{{CSP_NONCE_PLACEHOLDER}}"></script>',
|
||||
'<script></script>',
|
||||
'</head><body><div id="root"></div></body></html>',
|
||||
].join('');
|
||||
|
||||
const RENDERED_INDEX_DOCUMENT = [
|
||||
'<!doctype html><html lang="en"><head>',
|
||||
'<link rel="preconnect" href="https://cdn.fluxer.test">',
|
||||
'<script nonce="abc123">window.__FLUXER_BOOTSTRAP__={"instance":{}};</script>',
|
||||
'<script>window.__FLUXER_BOOTSTRAP__={"instance":{}};</script>',
|
||||
'</head><body><div id="root"></div></body></html>',
|
||||
].join('');
|
||||
|
||||
|
||||
@@ -344,14 +344,6 @@ const BOOTSTRAP_ENDPOINT = 'https://primary.test/api';
|
||||
registration: {collect_date_of_birth: true},
|
||||
},
|
||||
},
|
||||
geoip: {
|
||||
countryCode: null,
|
||||
regionCode: null,
|
||||
latitude: null,
|
||||
longitude: null,
|
||||
ageRestrictedGeos: [],
|
||||
ageBlockedGeos: [],
|
||||
},
|
||||
};
|
||||
|
||||
const {VoiceEngineV2AppScreenShareExecutionAdapter, shouldRestoreScreenShareAfterReconnect} = await import(
|
||||
|
||||
@@ -16,6 +16,7 @@ rand = "0.10"
|
||||
reqwest = { version = "0.13.5", default-features = false, features = ["json", "rustls", "stream", "gzip", "brotli", "deflate"] }
|
||||
serde = { version = "1.0.229", features = ["derive"] }
|
||||
serde_json = "1.0.151"
|
||||
sha2 = "0.11.0"
|
||||
tokio = { version = "1.53.1", features = ["macros", "net", "rt-multi-thread", "signal", "time", "fs"] }
|
||||
tokio-util = { version = "0.7.19", features = ["io"] }
|
||||
tower = { version = "0.5.3", features = ["util"] }
|
||||
|
||||
@@ -9,7 +9,6 @@ use serde::Serialize;
|
||||
pub struct BootstrapPayload<'a> {
|
||||
pub config: BootstrapConfig<'a>,
|
||||
pub instance: &'a serde_json::Value,
|
||||
pub geoip: &'a serde_json::Value,
|
||||
}
|
||||
|
||||
#[derive(Serialize)]
|
||||
@@ -38,12 +37,7 @@ struct LegacyConfig<'a> {
|
||||
bootstrap_api_public_endpoint: Option<&'a str>,
|
||||
}
|
||||
|
||||
pub fn build_bootstrap_script(
|
||||
config: &AppProxyConfig,
|
||||
discovery: &DiscoveryResponse,
|
||||
geoip: &serde_json::Value,
|
||||
nonce: &str,
|
||||
) -> String {
|
||||
pub fn build_bootstrap_script(config: &AppProxyConfig, discovery: &DiscoveryResponse) -> String {
|
||||
let api_public_endpoint =
|
||||
api_public_endpoint(config.bootstrap_api_public_endpoint.as_deref(), discovery);
|
||||
|
||||
@@ -54,7 +48,6 @@ pub fn build_bootstrap_script(
|
||||
bootstrap_api_public_endpoint: api_public_endpoint,
|
||||
},
|
||||
instance: &discovery.data,
|
||||
geoip,
|
||||
};
|
||||
|
||||
let legacy = LegacyConfig {
|
||||
@@ -67,7 +60,7 @@ pub fn build_bootstrap_script(
|
||||
let legacy_json = escape_json_for_script(&serde_json::to_string(&legacy).unwrap());
|
||||
|
||||
format!(
|
||||
r#"<script nonce="{nonce}">window.__FLUXER_BOOTSTRAP__={bootstrap_json};window.__FLUXER_CONFIG__={legacy_json};</script>"#
|
||||
r#"<script>window.__FLUXER_BOOTSTRAP__={bootstrap_json};window.__FLUXER_CONFIG__={legacy_json};</script>"#
|
||||
)
|
||||
}
|
||||
|
||||
@@ -144,7 +137,6 @@ const STATIC_PRECONNECT_TAGS: [&str; 2] = [
|
||||
|
||||
pub fn inject_bootstrap(
|
||||
html: &str,
|
||||
nonce: &str,
|
||||
script_tag: &str,
|
||||
static_cdn_endpoint: &str,
|
||||
media_endpoint: &str,
|
||||
@@ -152,35 +144,34 @@ pub fn inject_bootstrap(
|
||||
let static_cdn = static_cdn_endpoint.trim_end_matches('/');
|
||||
let media = media_endpoint.trim_end_matches('/');
|
||||
|
||||
let nonced = html.replace("{{CSP_NONCE_PLACEHOLDER}}", nonce);
|
||||
let nonced = apply_static_preconnect(nonced, static_cdn);
|
||||
let nonced = nonced.replace("{{STATIC_CDN_ENDPOINT}}", static_cdn);
|
||||
let nonced = apply_media_preconnect(&nonced, media, static_cdn);
|
||||
let html = apply_static_preconnect(html.to_owned(), static_cdn);
|
||||
let html = html.replace("{{STATIC_CDN_ENDPOINT}}", static_cdn);
|
||||
let html = apply_media_preconnect(&html, media, static_cdn);
|
||||
|
||||
if nonced.contains("<!--{{FLUXER_BOOTSTRAP}}-->") {
|
||||
return nonced.replace("<!--{{FLUXER_BOOTSTRAP}}-->", script_tag);
|
||||
if html.contains("<!--{{FLUXER_BOOTSTRAP}}-->") {
|
||||
return html.replace("<!--{{FLUXER_BOOTSTRAP}}-->", script_tag);
|
||||
}
|
||||
if nonced.contains("{{FLUXER_BOOTSTRAP}}") {
|
||||
return nonced.replace("{{FLUXER_BOOTSTRAP}}", script_tag);
|
||||
if html.contains("{{FLUXER_BOOTSTRAP}}") {
|
||||
return html.replace("{{FLUXER_BOOTSTRAP}}", script_tag);
|
||||
}
|
||||
|
||||
let insert_at = nonced
|
||||
let insert_at = html
|
||||
.find("<head>")
|
||||
.map(|pos| pos + "<head>".len())
|
||||
.or_else(|| {
|
||||
let pos = nonced.find("<head ")?;
|
||||
nonced[pos..].find('>').map(|close| pos + close + 1)
|
||||
let pos = html.find("<head ")?;
|
||||
html[pos..].find('>').map(|close| pos + close + 1)
|
||||
});
|
||||
if let Some(insert_at) = insert_at {
|
||||
let mut result = String::with_capacity(nonced.len() + script_tag.len() + 3);
|
||||
result.push_str(&nonced[..insert_at]);
|
||||
let mut result = String::with_capacity(html.len() + script_tag.len() + 3);
|
||||
result.push_str(&html[..insert_at]);
|
||||
result.push_str("\n\t\t");
|
||||
result.push_str(script_tag);
|
||||
result.push_str(&nonced[insert_at..]);
|
||||
result.push_str(&html[insert_at..]);
|
||||
return result;
|
||||
}
|
||||
|
||||
nonced
|
||||
html
|
||||
}
|
||||
|
||||
fn apply_static_preconnect(mut html: String, static_cdn: &str) -> String {
|
||||
@@ -219,7 +210,6 @@ mod tests {
|
||||
fn inject_into_shipped_shell() -> String {
|
||||
inject_bootstrap(
|
||||
SHIPPED_APP_SHELL,
|
||||
"shellnonce",
|
||||
"<script>boot</script>",
|
||||
"https://cdn.example.test/",
|
||||
"https://media.example.test/",
|
||||
@@ -256,16 +246,20 @@ mod tests {
|
||||
let result = inject_into_shipped_shell();
|
||||
assert!(!result.contains("{{STATIC_CDN_ENDPOINT}}"));
|
||||
assert!(!result.contains("{{MEDIA_ENDPOINT}}"));
|
||||
assert!(!result.contains("{{CSP_NONCE_PLACEHOLDER}}"));
|
||||
assert!(!result.contains("{{FLUXER_BOOTSTRAP}}"));
|
||||
assert!(result.contains("<script>boot</script>"));
|
||||
assert!(result.contains(r#"nonce="shellnonce""#));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn shipped_shell_carries_no_nonce_attribute_or_placeholder() {
|
||||
assert!(!SHIPPED_APP_SHELL.contains("nonce"));
|
||||
assert!(!SHIPPED_APP_SHELL.contains("{{CSP_NONCE_PLACEHOLDER}}"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn inject_bootstrap_before_head_close() {
|
||||
let html = "<html><head><title>App</title></head><body></body></html>";
|
||||
let result = inject_bootstrap(html, "abc123", "<script>boot</script>", "", "");
|
||||
let result = inject_bootstrap(html, "<script>boot</script>", "", "");
|
||||
assert!(result.contains("<script>boot</script>"));
|
||||
assert!(result.contains("<head>"));
|
||||
}
|
||||
@@ -273,7 +267,7 @@ mod tests {
|
||||
#[test]
|
||||
fn inject_bootstrap_fluxer_placeholder() {
|
||||
let html = "<html><head>{{FLUXER_BOOTSTRAP}}</head></html>";
|
||||
let result = inject_bootstrap(html, "n1", "<script>x</script>", "", "");
|
||||
let result = inject_bootstrap(html, "<script>x</script>", "", "");
|
||||
assert!(result.contains("<script>x</script>"));
|
||||
assert!(!result.contains("{{FLUXER_BOOTSTRAP}}"));
|
||||
}
|
||||
@@ -281,25 +275,16 @@ mod tests {
|
||||
#[test]
|
||||
fn inject_bootstrap_comment_placeholder() {
|
||||
let html = "<html><head><!--{{FLUXER_BOOTSTRAP}}--></head></html>";
|
||||
let result = inject_bootstrap(html, "n2", "<script>y</script>", "", "");
|
||||
let result = inject_bootstrap(html, "<script>y</script>", "", "");
|
||||
assert!(result.contains("<script>y</script>"));
|
||||
assert!(!result.contains("<!--{{FLUXER_BOOTSTRAP}}-->"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn inject_bootstrap_replaces_csp_nonce_placeholder() {
|
||||
let html = r#"<html><head><script nonce="{{CSP_NONCE_PLACEHOLDER}}"></script>{{FLUXER_BOOTSTRAP}}</head></html>"#;
|
||||
let result = inject_bootstrap(html, "mynonce", "<script>z</script>", "", "");
|
||||
assert!(result.contains(r#"nonce="mynonce""#));
|
||||
assert!(!result.contains("{{CSP_NONCE_PLACEHOLDER}}"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn inject_bootstrap_replaces_static_cdn_endpoint_placeholder() {
|
||||
let html = r#"<html><head><link href="{{STATIC_CDN_ENDPOINT}}/web/favicon-32x32.png">{{FLUXER_BOOTSTRAP}}</head></html>"#;
|
||||
let result = inject_bootstrap(
|
||||
html,
|
||||
"nonce",
|
||||
"<script>boot</script>",
|
||||
"https://cdn.example.test/",
|
||||
"",
|
||||
@@ -315,7 +300,6 @@ mod tests {
|
||||
{{FLUXER_BOOTSTRAP}}</head></html>"#;
|
||||
let result = inject_bootstrap(
|
||||
html,
|
||||
"nonce",
|
||||
"<script>boot</script>",
|
||||
"https://cdn.example.test/",
|
||||
"https://media.example.test/",
|
||||
@@ -332,7 +316,6 @@ mod tests {
|
||||
{{FLUXER_BOOTSTRAP}}</head></html>"#;
|
||||
let result = inject_bootstrap(
|
||||
html,
|
||||
"nonce",
|
||||
"<script>boot</script>",
|
||||
"https://cdn.example.test",
|
||||
"",
|
||||
@@ -349,7 +332,6 @@ mod tests {
|
||||
{{FLUXER_BOOTSTRAP}}</head></html>"#;
|
||||
let result = inject_bootstrap(
|
||||
html,
|
||||
"nonce",
|
||||
"<script>boot</script>",
|
||||
"https://cdn.example.test",
|
||||
"https://cdn.example.test/",
|
||||
@@ -367,7 +349,6 @@ mod tests {
|
||||
fn static_cdn_keeps_a_credentialed_and_an_anonymous_preconnect() {
|
||||
let result = inject_bootstrap(
|
||||
SHELL_PRECONNECT_HEAD,
|
||||
"nonce",
|
||||
"<script>boot</script>",
|
||||
"https://cdn.example.test/",
|
||||
"https://media.example.test",
|
||||
@@ -384,7 +365,6 @@ mod tests {
|
||||
fn both_static_preconnects_are_dropped_when_the_endpoint_is_empty() {
|
||||
let result = inject_bootstrap(
|
||||
SHELL_PRECONNECT_HEAD,
|
||||
"nonce",
|
||||
"<script>boot</script>",
|
||||
"",
|
||||
"https://media.example.test",
|
||||
@@ -422,7 +402,6 @@ mod tests {
|
||||
#[test]
|
||||
fn bootstrap_payload_serialization_field_names() {
|
||||
let instance = serde_json::json!({"name": "test"});
|
||||
let geoip = serde_json::json!({"country": "SE"});
|
||||
let payload = BootstrapPayload {
|
||||
config: BootstrapConfig {
|
||||
release_channel: "stable",
|
||||
@@ -430,20 +409,18 @@ mod tests {
|
||||
bootstrap_api_public_endpoint: None,
|
||||
},
|
||||
instance: &instance,
|
||||
geoip: &geoip,
|
||||
};
|
||||
let json = serde_json::to_string(&payload).unwrap();
|
||||
assert!(json.contains(r#""releaseChannel""#));
|
||||
assert!(json.contains(r#""bootstrapApiEndpoint""#));
|
||||
assert!(json.contains(r#""config""#));
|
||||
assert!(json.contains(r#""instance""#));
|
||||
assert!(json.contains(r#""geoip""#));
|
||||
assert!(!json.contains("geoip"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn bootstrap_config_serializes_public_endpoint_when_present() {
|
||||
let instance = serde_json::json!({});
|
||||
let geoip = serde_json::json!({});
|
||||
let payload = BootstrapPayload {
|
||||
config: BootstrapConfig {
|
||||
release_channel: "canary",
|
||||
@@ -451,7 +428,6 @@ mod tests {
|
||||
bootstrap_api_public_endpoint: Some("https://pub.example.com/api"),
|
||||
},
|
||||
instance: &instance,
|
||||
geoip: &geoip,
|
||||
};
|
||||
let json = serde_json::to_string(&payload).unwrap();
|
||||
assert!(json.contains(r#""bootstrapApiPublicEndpoint""#));
|
||||
@@ -460,7 +436,6 @@ mod tests {
|
||||
#[test]
|
||||
fn bootstrap_config_omits_public_endpoint_when_none() {
|
||||
let instance = serde_json::json!({});
|
||||
let geoip = serde_json::json!({});
|
||||
let payload = BootstrapPayload {
|
||||
config: BootstrapConfig {
|
||||
release_channel: "stable",
|
||||
@@ -468,7 +443,6 @@ mod tests {
|
||||
bootstrap_api_public_endpoint: None,
|
||||
},
|
||||
instance: &instance,
|
||||
geoip: &geoip,
|
||||
};
|
||||
let json = serde_json::to_string(&payload).unwrap();
|
||||
assert!(!json.contains("bootstrapApiPublicEndpoint"));
|
||||
@@ -611,8 +585,7 @@ mod tests {
|
||||
let discovery = discovery_offering("https://chat.example.test:8443/api");
|
||||
let mut config = AppProxyConfig::from_env();
|
||||
config.bootstrap_api_public_endpoint = Some("https://chat.example.test/api".to_owned());
|
||||
let script =
|
||||
build_bootstrap_script(&config, &discovery, &serde_json::json!({}), "scriptnonce");
|
||||
let script = build_bootstrap_script(&config, &discovery);
|
||||
assert!(
|
||||
script.contains(r#""bootstrapApiPublicEndpoint":"https://chat.example.test:8443/api""#)
|
||||
);
|
||||
@@ -621,4 +594,16 @@ mod tests {
|
||||
));
|
||||
assert!(!script.contains(r#""https://chat.example.test/api""#));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_boot_script_is_a_bare_inline_script_with_nothing_per_visitor() {
|
||||
let discovery = discovery_offering("https://chat.example.test/api");
|
||||
let config = AppProxyConfig::from_env();
|
||||
let script = build_bootstrap_script(&config, &discovery);
|
||||
assert!(script.starts_with("<script>window.__FLUXER_BOOTSTRAP__="));
|
||||
assert!(script.ends_with("</script>"));
|
||||
assert!(!script.contains("nonce"));
|
||||
assert!(!script.contains("geoip"));
|
||||
assert!(!script.contains("countryCode"));
|
||||
}
|
||||
}
|
||||
|
||||
+177
-71
@@ -3,15 +3,82 @@
|
||||
use crate::config::{AppProxyConfig, CspConfig, CspSource, HttpEndpoint};
|
||||
use axum::http::HeaderValue;
|
||||
use axum::http::header::InvalidHeaderValue;
|
||||
use rand::RngExt;
|
||||
use base64::{Engine as _, engine::general_purpose::STANDARD};
|
||||
use sha2::{Digest, Sha256};
|
||||
|
||||
const CSP_NONCE_HEX_DIGITS: usize = 32;
|
||||
const CSP_VALIDATION_NONCE: &str = "00000000000000000000000000000000";
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
pub struct InlineScriptHash(String);
|
||||
|
||||
const _: () = assert!(
|
||||
CSP_VALIDATION_NONCE.len() == CSP_NONCE_HEX_DIGITS,
|
||||
"the nonce a policy is validated with must be shaped like the nonce a request carries"
|
||||
);
|
||||
impl InlineScriptHash {
|
||||
pub fn of(script_text: &str) -> Self {
|
||||
Self(format!(
|
||||
"'sha256-{}'",
|
||||
STANDARD.encode(Sha256::digest(script_text.as_bytes()))
|
||||
))
|
||||
}
|
||||
|
||||
pub fn as_source(&self) -> &str {
|
||||
&self.0
|
||||
}
|
||||
}
|
||||
|
||||
pub fn inline_script_hashes(document: &str) -> Vec<InlineScriptHash> {
|
||||
let mut hashes: Vec<InlineScriptHash> = Vec::new();
|
||||
let mut rest = document;
|
||||
while let Some((attributes, text, after)) = next_script_element(rest) {
|
||||
rest = after;
|
||||
if has_src_attribute(attributes) {
|
||||
continue;
|
||||
}
|
||||
let hash = InlineScriptHash::of(text);
|
||||
if !hashes.contains(&hash) {
|
||||
hashes.push(hash);
|
||||
}
|
||||
}
|
||||
hashes
|
||||
}
|
||||
|
||||
fn next_script_element(html: &str) -> Option<(&str, &str, &str)> {
|
||||
let mut offset = 0;
|
||||
loop {
|
||||
let start = offset + find_ignoring_ascii_case(&html[offset..], "<script")?;
|
||||
let name_end = start + "<script".len();
|
||||
let boundary = *html.as_bytes().get(name_end)?;
|
||||
if boundary != b'>' && boundary != b'/' && !boundary.is_ascii_whitespace() {
|
||||
offset = name_end;
|
||||
continue;
|
||||
}
|
||||
let tag_end = name_end + html[name_end..].find('>')?;
|
||||
let text_start = tag_end + 1;
|
||||
let text_end = text_start + find_ignoring_ascii_case(&html[text_start..], "</script")?;
|
||||
let close_end = html[text_end..]
|
||||
.find('>')
|
||||
.map_or(html.len(), |index| text_end + index + 1);
|
||||
return Some((
|
||||
&html[name_end..tag_end],
|
||||
&html[text_start..text_end],
|
||||
&html[close_end..],
|
||||
));
|
||||
}
|
||||
}
|
||||
|
||||
fn find_ignoring_ascii_case(haystack: &str, needle: &str) -> Option<usize> {
|
||||
haystack
|
||||
.as_bytes()
|
||||
.windows(needle.len())
|
||||
.position(|window| window.eq_ignore_ascii_case(needle.as_bytes()))
|
||||
}
|
||||
|
||||
fn has_src_attribute(attributes: &str) -> bool {
|
||||
attributes
|
||||
.split(|c: char| c.is_ascii_whitespace() || c == '/')
|
||||
.any(|token| {
|
||||
token
|
||||
.split('=')
|
||||
.next()
|
||||
.is_some_and(|name| name.eq_ignore_ascii_case("src"))
|
||||
})
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, Default)]
|
||||
pub struct RuntimeCspSources {
|
||||
@@ -129,7 +196,7 @@ impl CompiledCspPolicy {
|
||||
.map_err(CspCompileError::InvalidAssetPolicy)?;
|
||||
HeaderValue::from_str(&build_csp(
|
||||
&config,
|
||||
CSP_VALIDATION_NONCE,
|
||||
&[InlineScriptHash::of("")],
|
||||
configured_sources,
|
||||
))
|
||||
.map_err(CspCompileError::InvalidSpaPolicy)?;
|
||||
@@ -140,26 +207,24 @@ impl CompiledCspPolicy {
|
||||
self.asset.clone()
|
||||
}
|
||||
|
||||
pub fn spa_header(&self, nonce: &str, runtime_sources: &RuntimeCspSources) -> HeaderValue {
|
||||
assert!(
|
||||
nonce.len() == CSP_NONCE_HEX_DIGITS
|
||||
&& nonce.bytes().all(|byte| byte.is_ascii_hexdigit()),
|
||||
"a CSP nonce must be a 128-bit hexadecimal value"
|
||||
);
|
||||
HeaderValue::from_str(&build_csp(&self.config, nonce, runtime_sources)).expect(
|
||||
"every CSP source is a validated keyword, scheme, or ASCII origin, so a policy built \
|
||||
from them is always a valid header value",
|
||||
pub fn spa_header(
|
||||
&self,
|
||||
script_hashes: &[InlineScriptHash],
|
||||
runtime_sources: &RuntimeCspSources,
|
||||
) -> HeaderValue {
|
||||
HeaderValue::from_str(&build_csp(&self.config, script_hashes, runtime_sources)).expect(
|
||||
"every CSP source is a validated keyword, scheme, ASCII origin, or base64 hash, so a \
|
||||
policy built from them is always a valid header value",
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
pub fn generate_nonce() -> String {
|
||||
let bytes: [u8; 16] = rand::rng().random();
|
||||
hex::encode(bytes)
|
||||
}
|
||||
|
||||
fn build_csp(config: &CspConfig, nonce: &str, runtime_sources: &RuntimeCspSources) -> String {
|
||||
build_csp_directives(config, Some(nonce), runtime_sources).join("; ")
|
||||
fn build_csp(
|
||||
config: &CspConfig,
|
||||
script_hashes: &[InlineScriptHash],
|
||||
runtime_sources: &RuntimeCspSources,
|
||||
) -> String {
|
||||
build_csp_directives(config, Some(script_hashes), runtime_sources).join("; ")
|
||||
}
|
||||
|
||||
fn build_asset_csp(config: &CspConfig, runtime_sources: &RuntimeCspSources) -> String {
|
||||
@@ -168,7 +233,7 @@ fn build_asset_csp(config: &CspConfig, runtime_sources: &RuntimeCspSources) -> S
|
||||
|
||||
fn build_csp_directives(
|
||||
config: &CspConfig,
|
||||
nonce: Option<&str>,
|
||||
script_hashes: Option<&[InlineScriptHash]>,
|
||||
runtime_sources: &RuntimeCspSources,
|
||||
) -> Vec<String> {
|
||||
let mut directives = Vec::with_capacity(14);
|
||||
@@ -182,8 +247,8 @@ fn build_csp_directives(
|
||||
"'wasm-unsafe-eval'".to_owned(),
|
||||
"blob:".to_owned(),
|
||||
];
|
||||
if let Some(n) = nonce {
|
||||
script.insert(1, format!("'nonce-{n}'"));
|
||||
if let Some(hashes) = script_hashes {
|
||||
script.splice(1..1, hashes.iter().map(|hash| hash.as_source().to_owned()));
|
||||
}
|
||||
extend_from(&mut script, &config.extra_script_src, SCRIPT_SOURCES);
|
||||
extend_runtime_sources(&mut script, runtime_sources, true, false);
|
||||
@@ -290,21 +355,52 @@ fn extend_from(target: &mut Vec<String>, extra: &[CspSource], defaults: &[&str])
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn generate_nonce_produces_32_char_hex() {
|
||||
let nonce = generate_nonce();
|
||||
assert_eq!(nonce.len(), CSP_NONCE_HEX_DIGITS);
|
||||
assert!(nonce.chars().all(|c| c.is_ascii_hexdigit()));
|
||||
CompiledCspPolicy::compile(default_csp_config(), &runtime_sources())
|
||||
.unwrap()
|
||||
.spa_header(&nonce, &runtime_sources());
|
||||
fn hash_of(text: &str) -> InlineScriptHash {
|
||||
InlineScriptHash::of(text)
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn generate_nonce_is_random() {
|
||||
let a = generate_nonce();
|
||||
let b = generate_nonce();
|
||||
assert_ne!(a, b);
|
||||
fn an_inline_script_hash_is_the_base64_sha256_of_the_exact_script_text() {
|
||||
assert_eq!(
|
||||
hash_of("alert('Hello, world.');").as_source(),
|
||||
"'sha256-qznLcsROx4GACP2dm0UCKCzCG+HiZ1guq6ZZDob/Tng='"
|
||||
);
|
||||
assert_eq!(
|
||||
hash_of("").as_source(),
|
||||
"'sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU='"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn every_inline_script_is_hashed_and_external_scripts_are_not() {
|
||||
let document = concat!(
|
||||
"<head><script>first()</script>",
|
||||
"<SCRIPT type=\"text/javascript\">second()</SCRIPT >",
|
||||
"<script type=\"module\" src=\"/assets/app.js\"></script>",
|
||||
"<script defer src='/assets/vendor.js'></script>",
|
||||
"<scripts>not a script</scripts>",
|
||||
"<script data-src=\"x\">\nthird()\n</script></head>",
|
||||
);
|
||||
|
||||
assert_eq!(
|
||||
inline_script_hashes(document),
|
||||
vec![
|
||||
hash_of("first()"),
|
||||
hash_of("second()"),
|
||||
hash_of("\nthird()\n")
|
||||
]
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn an_inline_script_repeated_verbatim_is_granted_once() {
|
||||
let document = "<script>same()</script><script>same()</script>";
|
||||
assert_eq!(inline_script_hashes(document), vec![hash_of("same()")]);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn an_unterminated_script_is_never_granted() {
|
||||
assert!(inline_script_hashes("<script>never_closed()").is_empty());
|
||||
}
|
||||
|
||||
fn default_csp_config() -> CspConfig {
|
||||
@@ -322,7 +418,7 @@ mod tests {
|
||||
#[test]
|
||||
fn build_csp_includes_required_directives() {
|
||||
let config = default_csp_config();
|
||||
let csp = build_csp(&config, "testnonce", &runtime_sources());
|
||||
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
|
||||
assert!(csp.contains("default-src"));
|
||||
assert!(csp.contains("script-src"));
|
||||
assert!(csp.contains("style-src"));
|
||||
@@ -341,7 +437,7 @@ mod tests {
|
||||
#[test]
|
||||
fn build_csp_allows_blob_connections_for_camera_background_media() {
|
||||
let config = default_csp_config();
|
||||
let csp = build_csp(&config, "testnonce", &runtime_sources());
|
||||
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
|
||||
let connect = csp
|
||||
.split("; ")
|
||||
.find(|directive| directive.starts_with("connect-src "))
|
||||
@@ -369,22 +465,40 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_csp_includes_nonce_in_script_src() {
|
||||
fn build_csp_grants_each_script_hash_in_script_src_and_no_nonce() {
|
||||
let config = default_csp_config();
|
||||
let csp = build_csp(&config, "abc123def456", &runtime_sources());
|
||||
assert!(csp.contains("'nonce-abc123def456'"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_asset_csp_excludes_nonce() {
|
||||
let config = default_csp_config();
|
||||
let csp = build_asset_csp(&config, &runtime_sources());
|
||||
let csp = build_csp(
|
||||
&config,
|
||||
&[hash_of("first()"), hash_of("second()")],
|
||||
&runtime_sources(),
|
||||
);
|
||||
let script = csp
|
||||
.split("; ")
|
||||
.find(|directive| directive.starts_with("script-src "))
|
||||
.expect("script-src directive");
|
||||
assert!(script.starts_with(&format!(
|
||||
"script-src 'self' {} {} 'wasm-unsafe-eval' blob:",
|
||||
hash_of("first()").as_source(),
|
||||
hash_of("second()").as_source()
|
||||
)));
|
||||
assert!(!csp.contains("nonce-"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_asset_csp_grants_no_inline_script() {
|
||||
let config = default_csp_config();
|
||||
let csp = build_asset_csp(&config, &runtime_sources());
|
||||
assert!(!csp.contains("nonce-"));
|
||||
assert!(!csp.contains("sha256-"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_csp_allows_no_third_party_captcha_hosts() {
|
||||
let csp = build_csp(&default_csp_config(), "test-nonce", &runtime_sources());
|
||||
let csp = build_csp(
|
||||
&default_csp_config(),
|
||||
&[hash_of("boot()")],
|
||||
&runtime_sources(),
|
||||
);
|
||||
assert!(!csp.contains("hcaptcha"));
|
||||
assert!(!csp.contains("challenges.cloudflare.com"));
|
||||
}
|
||||
@@ -392,7 +506,7 @@ mod tests {
|
||||
#[test]
|
||||
fn csp_no_double_spaces_or_trailing_semicolons() {
|
||||
let config = default_csp_config();
|
||||
let csp = build_csp(&config, "nonce1", &runtime_sources());
|
||||
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
|
||||
assert!(!csp.contains(" "), "CSP contains double spaces");
|
||||
assert!(!csp.ends_with(';'), "CSP ends with semicolon");
|
||||
assert!(!csp.ends_with("; "), "CSP ends with semicolon+space");
|
||||
@@ -410,14 +524,14 @@ mod tests {
|
||||
),
|
||||
..Default::default()
|
||||
};
|
||||
let csp = build_csp(&config, "nonce1", &runtime_sources());
|
||||
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
|
||||
assert!(csp.contains("report-uri https://example.com/csp-report"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn build_csp_excludes_report_uri_when_none() {
|
||||
let config = default_csp_config();
|
||||
let csp = build_csp(&config, "nonce1", &runtime_sources());
|
||||
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources());
|
||||
assert!(!csp.contains("report-uri"));
|
||||
}
|
||||
|
||||
@@ -429,7 +543,7 @@ mod tests {
|
||||
media_endpoint: Some(endpoint("https://media.example.test")),
|
||||
..Default::default()
|
||||
};
|
||||
let csp = build_csp(&config, "nonce1", &runtime_sources);
|
||||
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources);
|
||||
assert!(csp.contains("style-src 'self' 'unsafe-inline'"));
|
||||
assert!(csp.contains("https://static.example.test"));
|
||||
assert!(csp.contains("https://media.example.test"));
|
||||
@@ -471,7 +585,7 @@ mod tests {
|
||||
..Default::default()
|
||||
};
|
||||
|
||||
let csp = build_csp(&config, "nonce1", &runtime_sources);
|
||||
let csp = build_csp(&config, &[hash_of("boot()")], &runtime_sources);
|
||||
|
||||
assert!(csp.contains("http://localhost:3900"));
|
||||
assert!(csp.contains("http://fluxer-uploads.localhost:3900"));
|
||||
@@ -492,6 +606,7 @@ mod tests {
|
||||
let asset = policy.asset_header();
|
||||
let asset = asset.to_str().unwrap();
|
||||
assert!(!asset.contains("nonce-"));
|
||||
assert!(!asset.contains("sha256-"));
|
||||
assert!(asset.contains("https://static.example.test"));
|
||||
assert!(
|
||||
!asset.contains("https://media.example.test"),
|
||||
@@ -501,7 +616,7 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_compiled_policy_stamps_the_requests_own_nonce_and_discovery_endpoints() {
|
||||
fn a_compiled_policy_stamps_the_documents_script_hashes_and_discovery_endpoints() {
|
||||
let policy = CompiledCspPolicy::compile(default_csp_config(), &runtime_sources()).unwrap();
|
||||
let discovered = RuntimeCspSources {
|
||||
static_cdn_endpoint: Some(endpoint("https://cdn.discovered.test")),
|
||||
@@ -509,10 +624,10 @@ mod tests {
|
||||
..Default::default()
|
||||
};
|
||||
|
||||
let header = policy.spa_header("0123456789abcdef0123456789abcdef", &discovered);
|
||||
let header = policy.spa_header(&[hash_of("boot()")], &discovered);
|
||||
let header = header.to_str().unwrap();
|
||||
|
||||
assert!(header.contains("'nonce-0123456789abcdef0123456789abcdef'"));
|
||||
assert!(header.contains(hash_of("boot()").as_source()));
|
||||
assert!(header.contains("https://cdn.discovered.test"));
|
||||
assert!(header.contains("https://branding.discovered.test"));
|
||||
}
|
||||
@@ -530,19 +645,10 @@ mod tests {
|
||||
policy.asset_header().to_str().unwrap(),
|
||||
build_asset_csp(&config, &sources)
|
||||
);
|
||||
let hashes = [hash_of("boot()")];
|
||||
assert_eq!(
|
||||
policy
|
||||
.spa_header(CSP_VALIDATION_NONCE, &sources)
|
||||
.to_str()
|
||||
.unwrap(),
|
||||
build_csp(&config, CSP_VALIDATION_NONCE, &sources)
|
||||
policy.spa_header(&hashes, &sources).to_str().unwrap(),
|
||||
build_csp(&config, &hashes, &sources)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
#[should_panic(expected = "a CSP nonce must be a 128-bit hexadecimal value")]
|
||||
fn a_compiled_policy_refuses_a_nonce_it_did_not_generate() {
|
||||
let policy = CompiledCspPolicy::compile(default_csp_config(), &runtime_sources()).unwrap();
|
||||
policy.spa_header("not-a-nonce", &runtime_sources());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,97 @@
|
||||
// SPDX-License-Identifier: AGPL-3.0-or-later
|
||||
|
||||
use crate::geoip::build_geoip_response;
|
||||
use crate::state::AppState;
|
||||
use axum::{
|
||||
Json,
|
||||
extract::State,
|
||||
http::{HeaderMap, HeaderValue, header},
|
||||
response::{IntoResponse, Response},
|
||||
};
|
||||
|
||||
pub const CLIENT_GEOIP_PATH: &str = "/_geoip";
|
||||
const CLIENT_GEOIP_CACHE_CONTROL: &str = "no-store, private";
|
||||
|
||||
pub async fn client_geoip(State(state): State<AppState>, headers: HeaderMap) -> Response {
|
||||
let mut response = Json(build_geoip_response(state.geoip.lookup(&headers))).into_response();
|
||||
response.headers_mut().insert(
|
||||
header::CACHE_CONTROL,
|
||||
HeaderValue::from_static(CLIENT_GEOIP_CACHE_CONTROL),
|
||||
);
|
||||
response
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use crate::config::AppProxyConfig;
|
||||
use crate::discovery_cache::DiscoveryCache;
|
||||
use crate::routes::build_router;
|
||||
use axum::body::Body;
|
||||
use axum::http::{Request, StatusCode};
|
||||
use fluxer_common::config::GeoipSourceConfig;
|
||||
use fluxer_common::geoip::{GeoipConfig, GeoipLookup, GeoipResolver};
|
||||
use std::sync::Arc;
|
||||
use tower::ServiceExt;
|
||||
|
||||
fn geoip_state() -> AppState {
|
||||
let config = AppProxyConfig::from_env();
|
||||
let csp = Arc::new(
|
||||
crate::csp::CompiledCspPolicy::from_config(&config)
|
||||
.expect("the test configuration must compile to a valid CSP"),
|
||||
);
|
||||
AppState {
|
||||
config: Arc::new(config),
|
||||
csp,
|
||||
http_client: reqwest::Client::new(),
|
||||
discovery_cache: Arc::new(DiscoveryCache::new()),
|
||||
geoip: Arc::new(GeoipResolver::from_config(&GeoipConfig {
|
||||
geoip_source: GeoipSourceConfig::Filesystem {
|
||||
maxmind_db_path: None,
|
||||
},
|
||||
geoip_s3_config: None,
|
||||
trust_client_ip_header: true,
|
||||
client_ip_header_name: "x-forwarded-for".to_owned(),
|
||||
})),
|
||||
index_html: Some(Arc::from("<html><head></head><body></body></html>")),
|
||||
budgets: crate::state::AppProxyBudgets::default(),
|
||||
}
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn the_geoip_endpoint_answers_for_the_requesting_client_and_is_never_stored() {
|
||||
let response = build_router(geoip_state())
|
||||
.oneshot(
|
||||
Request::get(CLIENT_GEOIP_PATH)
|
||||
.header("x-forwarded-for", "203.0.113.10")
|
||||
.body(Body::empty())
|
||||
.unwrap(),
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
|
||||
assert_eq!(response.status(), StatusCode::OK);
|
||||
let headers = response.headers();
|
||||
assert_eq!(
|
||||
headers.get(header::CACHE_CONTROL).unwrap(),
|
||||
CLIENT_GEOIP_CACHE_CONTROL
|
||||
);
|
||||
assert!(
|
||||
headers
|
||||
.get(header::CONTENT_TYPE)
|
||||
.unwrap()
|
||||
.to_str()
|
||||
.unwrap()
|
||||
.starts_with("application/json"),
|
||||
"the SPA fallback answered the geoip endpoint with the app shell"
|
||||
);
|
||||
assert!(headers.get("x-fluxer-app-shell").is_none());
|
||||
|
||||
let body = axum::body::to_bytes(response.into_body(), usize::MAX)
|
||||
.await
|
||||
.unwrap();
|
||||
let body: serde_json::Value = serde_json::from_slice(&body).unwrap();
|
||||
assert_eq!(body, build_geoip_response(GeoipLookup::default()));
|
||||
assert_eq!(body["countryCode"], serde_json::Value::Null);
|
||||
}
|
||||
}
|
||||
@@ -3,6 +3,7 @@
|
||||
mod android_association;
|
||||
mod apple_association;
|
||||
mod assets_proxy;
|
||||
mod client_geoip;
|
||||
mod file_stream;
|
||||
mod health;
|
||||
mod spa_index;
|
||||
@@ -35,6 +36,10 @@ pub fn build_router(state: AppState) -> Router {
|
||||
Router::new()
|
||||
.route("/_health", get(health::health))
|
||||
.route("/_ready", get(health::ready))
|
||||
.route(
|
||||
client_geoip::CLIENT_GEOIP_PATH,
|
||||
get(client_geoip::client_geoip),
|
||||
)
|
||||
.route(
|
||||
"/.well-known/apple-app-site-association",
|
||||
get(apple_association::apple_app_site_association),
|
||||
|
||||
@@ -4,9 +4,8 @@ use crate::bootstrap::{
|
||||
build_bootstrap_script, inject_bootstrap, rewrite_endpoints_for_same_origin_host,
|
||||
};
|
||||
use crate::config::{AppProxyConfig, HttpEndpoint};
|
||||
use crate::csp::{RuntimeCspSources, generate_nonce};
|
||||
use crate::csp::{RuntimeCspSources, inline_script_hashes};
|
||||
use crate::discovery_cache::{DiscoveryResponse, discovery_endpoint};
|
||||
use crate::geoip::build_geoip_response;
|
||||
use crate::state::{
|
||||
AppProxyBudgets, AppState, MAX_RENDERED_SPA_INDEX_BYTES, MAX_SPA_INDEX_BYTES,
|
||||
read_bounded_text_file,
|
||||
@@ -27,6 +26,7 @@ use super::spa_static::{CORS_ALLOW_ANY_VALUE, guess_mime, is_font_mime};
|
||||
const ACCEPT_CH_VALUE: &str = "DPR, Sec-CH-DPR, Sec-CH-Width, Save-Data, ECT, Downlink";
|
||||
const CRITICAL_CH_VALUE: &str = "Sec-CH-DPR, Sec-CH-Width, Save-Data";
|
||||
const DEV_NO_STORE_CACHE_CONTROL: &str = "no-store, no-cache, must-revalidate, max-age=0";
|
||||
const SHARED_SHELL_CACHE_CONTROL: &str = "public, max-age=0, s-maxage=1";
|
||||
|
||||
pub async fn spa_catch_all(
|
||||
State(state): State<AppState>,
|
||||
@@ -154,7 +154,6 @@ async fn serve_spa_index(state: &AppState, headers: &HeaderMap) -> Response {
|
||||
rewrite_endpoints_for_same_origin_host(&mut discovery.data, host);
|
||||
}
|
||||
|
||||
let nonce = generate_nonce();
|
||||
let runtime_csp_sources = build_runtime_csp_sources(state, &discovery);
|
||||
let static_cdn_endpoint = runtime_csp_sources
|
||||
.static_cdn_endpoint
|
||||
@@ -164,9 +163,7 @@ async fn serve_spa_index(state: &AppState, headers: &HeaderMap) -> Response {
|
||||
.media_endpoint
|
||||
.as_ref()
|
||||
.map_or("", HttpEndpoint::as_str);
|
||||
let csp = state.csp.spa_header(&nonce, &runtime_csp_sources);
|
||||
let geoip = build_geoip_response(state.geoip.lookup(headers));
|
||||
let script_tag = build_bootstrap_script(&state.config, &discovery, &geoip, &nonce);
|
||||
let script_tag = build_bootstrap_script(&state.config, &discovery);
|
||||
|
||||
let raw_html = match load_spa_index_html(state).await {
|
||||
Ok(content) => content,
|
||||
@@ -181,7 +178,6 @@ async fn serve_spa_index(state: &AppState, headers: &HeaderMap) -> Response {
|
||||
let dev_buster = should_bust_dev_assets.then(current_dev_asset_cache_buster);
|
||||
let html = match render_spa_document(
|
||||
&raw_html,
|
||||
&nonce,
|
||||
&script_tag,
|
||||
static_cdn_endpoint,
|
||||
media_endpoint,
|
||||
@@ -193,8 +189,10 @@ async fn serve_spa_index(state: &AppState, headers: &HeaderMap) -> Response {
|
||||
return StatusCode::INTERNAL_SERVER_ERROR.into_response();
|
||||
}
|
||||
};
|
||||
let html = html.into_boxed_str();
|
||||
build_spa_response(html, csp, should_bust_dev_assets)
|
||||
let csp = state
|
||||
.csp
|
||||
.spa_header(&inline_script_hashes(&html), &runtime_csp_sources);
|
||||
build_spa_response(html.into_boxed_str(), csp, should_bust_dev_assets)
|
||||
}
|
||||
|
||||
fn same_origin_host<'a>(config: &'a AppProxyConfig, headers: &HeaderMap) -> Option<&'a str> {
|
||||
@@ -248,7 +246,6 @@ fn bounded_document(document: String) -> Result<String, SpaDocumentSizeLimitErro
|
||||
|
||||
fn render_spa_document(
|
||||
html: &str,
|
||||
nonce: &str,
|
||||
script_tag: &str,
|
||||
static_cdn_endpoint: &str,
|
||||
media_endpoint: &str,
|
||||
@@ -256,7 +253,6 @@ fn render_spa_document(
|
||||
) -> Result<String, SpaDocumentSizeLimitError> {
|
||||
let mut document = bounded_document(inject_bootstrap(
|
||||
html,
|
||||
nonce,
|
||||
script_tag,
|
||||
static_cdn_endpoint,
|
||||
media_endpoint,
|
||||
@@ -457,7 +453,10 @@ fn build_spa_response(html: Box<str>, csp: HeaderValue, dev_no_store: bool) -> R
|
||||
HeaderValue::from_static("no-store"),
|
||||
);
|
||||
} else {
|
||||
headers.insert(header::CACHE_CONTROL, HeaderValue::from_static("no-cache"));
|
||||
headers.insert(
|
||||
header::CACHE_CONTROL,
|
||||
HeaderValue::from_static(SHARED_SHELL_CACHE_CONTROL),
|
||||
);
|
||||
}
|
||||
super::set_security_headers(headers);
|
||||
headers.insert(
|
||||
@@ -664,13 +663,12 @@ mod tests {
|
||||
assert!(!is_static_root_file("/users/1.2.3"));
|
||||
}
|
||||
|
||||
const SHELL_WITH_A_NONCE_HOLE: &str = r#"<!doctype html><html><head><title>Fluxer</title><script nonce="{{CSP_NONCE_PLACEHOLDER}}"></script><script src="/assets/app.js"></script></head><body></body></html>"#;
|
||||
const SHELL_WITH_AN_INLINE_SCRIPT: &str = r#"<!doctype html><html><head><title>Fluxer</title><script>inline()</script><script src="/assets/app.js"></script></head><body></body></html>"#;
|
||||
|
||||
#[test]
|
||||
fn the_rendered_document_always_carries_the_bootstrap_and_a_real_nonce() {
|
||||
fn the_rendered_document_always_carries_the_bootstrap() {
|
||||
let rendered = render_spa_document(
|
||||
SHELL_WITH_A_NONCE_HOLE,
|
||||
"reqnonce",
|
||||
SHELL_WITH_AN_INLINE_SCRIPT,
|
||||
"<script>booted</script>",
|
||||
"https://static.example.test",
|
||||
"",
|
||||
@@ -678,16 +676,15 @@ mod tests {
|
||||
)
|
||||
.expect("test SPA document must render within its size limit");
|
||||
|
||||
assert!(!rendered.contains("{{CSP_NONCE_PLACEHOLDER}}"));
|
||||
assert!(rendered.contains(r#"nonce="reqnonce""#));
|
||||
assert!(rendered.contains("<script>booted</script>"));
|
||||
assert!(rendered.contains("<script>inline()</script>"));
|
||||
assert!(!rendered.contains("nonce"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn the_dev_cache_buster_reaches_the_rendered_document_only_when_supplied() {
|
||||
let busted = render_spa_document(
|
||||
SHELL_WITH_A_NONCE_HOLE,
|
||||
"reqnonce",
|
||||
SHELL_WITH_AN_INLINE_SCRIPT,
|
||||
"<script>booted</script>",
|
||||
"",
|
||||
"",
|
||||
@@ -695,8 +692,7 @@ mod tests {
|
||||
)
|
||||
.expect("test SPA document must render within its size limit");
|
||||
let untouched = render_spa_document(
|
||||
SHELL_WITH_A_NONCE_HOLE,
|
||||
"reqnonce",
|
||||
SHELL_WITH_AN_INLINE_SCRIPT,
|
||||
"<script>booted</script>",
|
||||
"",
|
||||
"",
|
||||
@@ -712,13 +708,12 @@ mod tests {
|
||||
const SHELL_WITH_ENDPOINT_HOLES: &str = r#"<!doctype html><html><head><title>Fluxer</title><link rel="preconnect" href="{{STATIC_CDN_ENDPOINT}}">
|
||||
<link rel="preconnect" href="{{STATIC_CDN_ENDPOINT}}" crossorigin>
|
||||
<link rel="preconnect" href="{{MEDIA_ENDPOINT}}">
|
||||
<link rel="icon" type="image/png" sizes="32x32" href="{{STATIC_CDN_ENDPOINT}}/web/favicon-32x32.png"><link rel="apple-touch-icon" sizes="180x180" href="{{STATIC_CDN_ENDPOINT}}/web/apple-touch-icon.png"><script nonce="{{CSP_NONCE_PLACEHOLDER}}"></script><script src="/assets/app.js"></script></head><body></body></html>"#;
|
||||
<link rel="icon" type="image/png" sizes="32x32" href="{{STATIC_CDN_ENDPOINT}}/web/favicon-32x32.png"><link rel="apple-touch-icon" sizes="180x180" href="{{STATIC_CDN_ENDPOINT}}/web/apple-touch-icon.png"><script>inline()</script><script src="/assets/app.js"></script></head><body></body></html>"#;
|
||||
|
||||
#[test]
|
||||
fn the_static_cdn_argument_resolves_every_hole_the_shell_carries() {
|
||||
let rendered = render_spa_document(
|
||||
SHELL_WITH_ENDPOINT_HOLES,
|
||||
"reqnonce",
|
||||
"<script>booted</script>",
|
||||
"https://cdn.example.test/",
|
||||
"https://media.example.test",
|
||||
@@ -751,7 +746,6 @@ mod tests {
|
||||
fn the_media_argument_is_resolved_and_weighed_against_the_static_cdn() {
|
||||
let distinct = render_spa_document(
|
||||
SHELL_WITH_ENDPOINT_HOLES,
|
||||
"reqnonce",
|
||||
"<script>booted</script>",
|
||||
"https://cdn.example.test",
|
||||
"https://media.example.test/",
|
||||
@@ -767,7 +761,6 @@ mod tests {
|
||||
|
||||
let shared = render_spa_document(
|
||||
SHELL_WITH_ENDPOINT_HOLES,
|
||||
"reqnonce",
|
||||
"<script>booted</script>",
|
||||
"https://cdn.example.test",
|
||||
"https://cdn.example.test",
|
||||
@@ -934,21 +927,72 @@ mod tests {
|
||||
}
|
||||
}
|
||||
|
||||
fn nonce_granted_by(response: &Response) -> String {
|
||||
let policy = response
|
||||
fn policy_of(response: &Response) -> String {
|
||||
response
|
||||
.headers()
|
||||
.get(header::CONTENT_SECURITY_POLICY)
|
||||
.expect("the document was served without a content security policy")
|
||||
.to_str()
|
||||
.unwrap();
|
||||
let opening = policy
|
||||
.find("'nonce-")
|
||||
.expect("the content security policy granted no nonce at all");
|
||||
let remainder = &policy[opening + "'nonce-".len()..];
|
||||
let closing = remainder
|
||||
.find('\'')
|
||||
.expect("the content security policy left its nonce source unterminated");
|
||||
remainder[..closing].to_owned()
|
||||
.unwrap()
|
||||
.to_owned()
|
||||
}
|
||||
|
||||
fn script_hashes_granted_by(policy: &str) -> Vec<String> {
|
||||
policy
|
||||
.split("; ")
|
||||
.find(|directive| directive.starts_with("script-src "))
|
||||
.expect("the content security policy has no script-src directive")
|
||||
.split(' ')
|
||||
.filter(|source| source.starts_with("'sha256-"))
|
||||
.map(str::to_owned)
|
||||
.collect()
|
||||
}
|
||||
|
||||
fn bare_inline_scripts_in(document: &str) -> Vec<&str> {
|
||||
document
|
||||
.split("<script>")
|
||||
.skip(1)
|
||||
.map(|rest| {
|
||||
&rest[..rest
|
||||
.find("</script>")
|
||||
.expect("an inline script in the served document is never closed")]
|
||||
})
|
||||
.collect()
|
||||
}
|
||||
|
||||
fn sha256_source(text: &str) -> String {
|
||||
use base64::Engine as _;
|
||||
use sha2::Digest as _;
|
||||
format!(
|
||||
"'sha256-{}'",
|
||||
base64::engine::general_purpose::STANDARD.encode(sha2::Sha256::digest(text))
|
||||
)
|
||||
}
|
||||
|
||||
fn assert_every_inline_script_is_granted(document: &str, policy: &str) {
|
||||
for tag in document.split("<script").skip(1) {
|
||||
let tag = &tag[..tag.find('>').unwrap()];
|
||||
assert!(
|
||||
tag.is_empty() || tag.contains(" src="),
|
||||
"the served document carries a script tag the test cannot classify: <script{tag}>"
|
||||
);
|
||||
}
|
||||
let inline = bare_inline_scripts_in(document);
|
||||
assert!(
|
||||
!inline.is_empty(),
|
||||
"the served document carries no inline script at all"
|
||||
);
|
||||
let mut expected: Vec<String> = inline.iter().map(|script| sha256_source(script)).collect();
|
||||
expected.sort();
|
||||
expected.dedup();
|
||||
let mut granted = script_hashes_granted_by(policy);
|
||||
granted.sort();
|
||||
assert_eq!(
|
||||
granted, expected,
|
||||
"the policy must grant exactly the inline scripts the document carries"
|
||||
);
|
||||
assert!(!document.contains("nonce"));
|
||||
assert!(!policy.contains("nonce"));
|
||||
}
|
||||
|
||||
async fn read_document(response: Response) -> String {
|
||||
@@ -1059,26 +1103,14 @@ mod tests {
|
||||
|
||||
let response = serve_spa_index(&state, &HeaderMap::new()).await;
|
||||
assert_eq!(response.status(), StatusCode::OK);
|
||||
let granted_nonce = nonce_granted_by(&response);
|
||||
let policy = policy_of(&response);
|
||||
let served = read_document(response).await;
|
||||
|
||||
assert!(
|
||||
!served.contains("{{CSP_NONCE_PLACEHOLDER}}"),
|
||||
"the live branch shipped an unfilled nonce hole"
|
||||
);
|
||||
assert!(
|
||||
served.contains(&format!(
|
||||
r#"<script nonce="{granted_nonce}">window.__FLUXER_BOOTSTRAP__"#
|
||||
)),
|
||||
"the live bootstrap was not granted the nonce its own policy header carries"
|
||||
);
|
||||
assert_eq!(
|
||||
served
|
||||
.matches(&format!(r#"nonce="{granted_nonce}""#))
|
||||
.count(),
|
||||
served.matches(r#"nonce=""#).count(),
|
||||
"the live document carries a nonce its own policy header never granted"
|
||||
served.contains("<script>window.__FLUXER_BOOTSTRAP__"),
|
||||
"the live bootstrap is not a bare inline script"
|
||||
);
|
||||
assert_every_inline_script_is_granted(&served, &policy);
|
||||
assert!(
|
||||
!served.contains("{{STATIC_CDN_ENDPOINT}}"),
|
||||
"the live branch shipped an unresolved static CDN hole"
|
||||
@@ -1159,9 +1191,11 @@ mod tests {
|
||||
.to_str()
|
||||
.unwrap();
|
||||
assert_eq!(
|
||||
cache_control, "no-cache",
|
||||
"the document naming the hashed bundle must be revalidated on every load"
|
||||
cache_control, SHARED_SHELL_CACHE_CONTROL,
|
||||
"the document naming the hashed bundle must be revalidated on every load and held \
|
||||
by a shared cache for one second at most"
|
||||
);
|
||||
assert!(response.headers().get(header::SET_COOKIE).is_none());
|
||||
assert_ne!(
|
||||
cache_control, LONG_LIVED_ASSET_CACHE_CONTROL,
|
||||
"a shell cached for a year pins every returning visitor to the deployed-over bundle"
|
||||
@@ -1254,6 +1288,89 @@ mod tests {
|
||||
);
|
||||
}
|
||||
|
||||
fn request_from_visitor(ip: &str, country: &str, language: &str) -> HeaderMap {
|
||||
let mut headers = request_from_host("web.fluxer.app");
|
||||
for (name, value) in [
|
||||
("x-forwarded-for", ip),
|
||||
("cf-connecting-ip", ip),
|
||||
("cf-ipcountry", country),
|
||||
("accept-language", language),
|
||||
("cookie", "session=visitor-specific"),
|
||||
] {
|
||||
headers.insert(
|
||||
HeaderName::from_static(name),
|
||||
HeaderValue::from_str(value).unwrap(),
|
||||
);
|
||||
}
|
||||
headers
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn every_visitor_to_a_host_gets_a_byte_identical_shell_and_policy() {
|
||||
let mut state = assemble_spa_state(
|
||||
ReleaseChannel::Stable,
|
||||
Some(SHIPPED_APP_SHELL),
|
||||
DISCOVERY_BODY_WITH_WEB_APP_ENDPOINTS,
|
||||
None,
|
||||
None,
|
||||
)
|
||||
.await;
|
||||
let mut config = (*state.config).clone();
|
||||
config.same_origin_hosts = vec!["web.fluxer.app".to_owned()];
|
||||
config.trust_client_ip_header = true;
|
||||
state.config = Arc::new(config);
|
||||
|
||||
let stockholm =
|
||||
serve_spa_index(&state, &request_from_visitor("81.234.0.1", "SE", "sv-SE")).await;
|
||||
let sao_paulo =
|
||||
serve_spa_index(&state, &request_from_visitor("177.0.0.1", "BR", "pt-BR")).await;
|
||||
assert_eq!(stockholm.status(), StatusCode::OK);
|
||||
assert_eq!(sao_paulo.status(), StatusCode::OK);
|
||||
|
||||
let stockholm_policy = policy_of(&stockholm);
|
||||
let sao_paulo_policy = policy_of(&sao_paulo);
|
||||
assert_eq!(stockholm_policy, sao_paulo_policy);
|
||||
assert!(stockholm.headers().get(header::SET_COOKIE).is_none());
|
||||
assert!(sao_paulo.headers().get(header::SET_COOKIE).is_none());
|
||||
|
||||
let stockholm_body = read_document(stockholm).await;
|
||||
let sao_paulo_body = read_document(sao_paulo).await;
|
||||
assert_eq!(stockholm_body, sao_paulo_body);
|
||||
assert!(!stockholm_body.contains("geoip"));
|
||||
assert!(!stockholm_body.contains("countryCode"));
|
||||
assert_every_inline_script_is_granted(&stockholm_body, &stockholm_policy);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn the_shipped_shell_runs_every_inline_script_it_carries_under_its_policy() {
|
||||
let state = spa_state_serving(ReleaseChannel::Stable, Some(SHIPPED_APP_SHELL)).await;
|
||||
|
||||
let response = serve_spa_index(&state, &HeaderMap::new()).await;
|
||||
assert_eq!(response.status(), StatusCode::OK);
|
||||
let policy = policy_of(&response);
|
||||
let served = read_document(response).await;
|
||||
|
||||
assert_eq!(
|
||||
bare_inline_scripts_in(&served).len(),
|
||||
bare_inline_scripts_in(SHIPPED_APP_SHELL).len() + 1,
|
||||
"every inline script of fluxer_app/index.html plus the bootstrap must reach the document"
|
||||
);
|
||||
assert_every_inline_script_is_granted(&served, &policy);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn an_index_upstream_document_is_granted_after_its_dev_cache_buster() {
|
||||
let index_upstream_url = spawn_local_origin(SHIPPED_APP_SHELL, "text/html").await;
|
||||
let state = spa_state_reading_its_shell_from(index_upstream_url).await;
|
||||
|
||||
let response = serve_spa_index(&state, &HeaderMap::new()).await;
|
||||
assert_eq!(response.status(), StatusCode::OK);
|
||||
let policy = policy_of(&response);
|
||||
let served = read_document(response).await;
|
||||
|
||||
assert_every_inline_script_is_granted(&served, &policy);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn font_mime_types_are_cors_enabled() {
|
||||
assert!(is_font_mime("font/woff2"));
|
||||
|
||||
@@ -1570,7 +1570,7 @@ Defaults to the crate version. The reported build of `admin` and `app-proxy`. `B
|
||||
|
||||
## Content Security Policy
|
||||
|
||||
`app-proxy` builds a per-request nonce-based policy for the client HTML and the assets it serves. Each variable appends sources to one directive on top of the built-in ones. All are empty by default, and Compose forwards every one.
|
||||
`app-proxy` builds the policy for the client HTML and the assets it serves. The client HTML policy allows each inline script by its SHA-256 hash, so every visitor to a host gets the same document and header. Each variable appends sources to one directive on top of the built-in ones. All are empty by default, and Compose forwards every one.
|
||||
|
||||
Every name below goes in `.env`. `app-proxy` reads its environment at container start, so a change takes effect on `docker compose up -d app-proxy`. A `docker compose restart app-proxy` does not apply it.
|
||||
|
||||
|
||||
@@ -395,6 +395,7 @@ Forward every path and query string unchanged. The edge handles routing:
|
||||
| `/.well-known/apple-app-site-association`, `/apple-app-site-association` | Apple app association |
|
||||
| `/.well-known/assetlinks.json` | Android app association |
|
||||
| `/version.json` | Client version metadata |
|
||||
| `/_geoip` | Client location lookup |
|
||||
|
||||
All other paths serve the web app. The admin path follows `FLUXER_ADMIN_BASE_PATH`, `/admin` by default.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user