Summary
The
Public App Identity settings allow administrators to configure branding assets using URLs, including:
- Icon URL
- Symbol URL
- Logo URL
- Wordmark URL
- Favicon URL
The configured URLs are accepted and stored correctly.
However, if a branding asset is hosted on a different origin (for example the parent domain
https://example.com while the Fluxer instance itself runs on
https://chat.example.com), the asset is blocked by Fluxer's own
img-src Content Security Policy.
As a result, the configured branding is never displayed and the default Fluxer branding remains visible.
This report is
not about general CSP customization, LiveKit, Cloudflare Turnstile, custom themes or loading arbitrary third-party resources.
It specifically concerns the official
Public App Identity branding feature.
The current behavior is inconsistent because the admin UI accepts and stores branding asset URLs which are subsequently blocked by the frontend through its own Content Security Policy.
Using a parent domain to host shared branding assets is a common deployment pattern for self-hosted services.
For example:
https://example.comhttps://chat.example.comhttps://cloud.example.comhttps://status.example.com
In this scenario the branding assets belong to the same deployment and are not unrelated third-party resources.
Before opening this report I searched through the existing CSP-related issues and discussions.
The existing reports I found mainly concern:
- LiveKit (
connect-src) - Cloudflare Turnstile (
script-src / frame-src) - Custom themes
- General CSP configuration
I could not find an existing report specifically covering the official
Public App Identity branding feature.
Steps to reproduce
- Deploy a self-hosted Fluxer instance on a subdomain.
Example:
https://chat.example.com
- Host a branding asset on the parent domain.
Example:
https://example.com/assets/branding/favicon.ico
- Open:
Admin → Instance Configuration → Public App Identity
- Set the Favicon URL to the URL above.
- Save the configuration.
- Reload the login page.
- Open the browser developer console.
- Observe that the favicon is not loaded and the browser reports an
img-src Content Security Policy violation.
Environment
Deployment: Docker Compose
Operating System: AlmaLinux 9
Browser: Firefox 151
Logs or screenshots
image
image
image
image
The browser reports the following CSP violation:
Content-Security-Policy: The page's settings blocked the loading of a resource (img-src) at https://example.com/assets/branding/favicon.ico because it violates the following directive:
img-src 'self' blob: data:
https://*.fluxer.app
https://i.ytimg.com
https://*.youtube.com
https://*.fluxer.media
https://fluxer.media
https://chat.example.com
https://chat.example.com/media
The favicon itself is publicly accessible and loads correctly when opened directly in the browser.
Fluxer stores the configured URL successfully, but the browser blocks the request because the parent domain is not included in the generated
img-src CSP.
Comments
No comments yet.