[Self-Hosted] Branding asset URLs configured in "Public App Identity" are blocked by img-src CSP

(#710) Bug Fixed self-hosting

Summary

The Public App Identity settings allow administrators to configure branding assets using URLs, including:
  • Icon URL
  • Symbol URL
  • Logo URL
  • Wordmark URL
  • Favicon URL
The configured URLs are accepted and stored correctly. However, if a branding asset is hosted on a different origin (for example the parent domain https://example.com while the Fluxer instance itself runs on https://chat.example.com), the asset is blocked by Fluxer's own img-src Content Security Policy. As a result, the configured branding is never displayed and the default Fluxer branding remains visible. This report is not about general CSP customization, LiveKit, Cloudflare Turnstile, custom themes or loading arbitrary third-party resources. It specifically concerns the official Public App Identity branding feature. The current behavior is inconsistent because the admin UI accepts and stores branding asset URLs which are subsequently blocked by the frontend through its own Content Security Policy. Using a parent domain to host shared branding assets is a common deployment pattern for self-hosted services. For example:
  • https://example.com
  • https://chat.example.com
  • https://cloud.example.com
  • https://status.example.com
In this scenario the branding assets belong to the same deployment and are not unrelated third-party resources. Before opening this report I searched through the existing CSP-related issues and discussions. The existing reports I found mainly concern:
  • LiveKit (connect-src)
  • Cloudflare Turnstile (script-src / frame-src)
  • Custom themes
  • General CSP configuration
I could not find an existing report specifically covering the official Public App Identity branding feature.

Steps to reproduce

  1. Deploy a self-hosted Fluxer instance on a subdomain.
Example: https://chat.example.com
  1. Host a branding asset on the parent domain.
Example: https://example.com/assets/branding/favicon.ico
  1. Open:
Admin → Instance Configuration → Public App Identity
  1. Set the Favicon URL to the URL above.
  1. Save the configuration.
  1. Reload the login page.
  1. Open the browser developer console.
  1. Observe that the favicon is not loaded and the browser reports an img-src Content Security Policy violation.

Environment

Deployment: Docker Compose Operating System: AlmaLinux 9 Browser: Firefox 151

Logs or screenshots

image image image image The browser reports the following CSP violation:
Content-Security-Policy: The page's settings blocked the loading of a resource (img-src) at https://example.com/assets/branding/favicon.ico because it violates the following directive:

img-src 'self' blob: data:
https://*.fluxer.app
https://i.ytimg.com
https://*.youtube.com
https://*.fluxer.media
https://fluxer.media
https://chat.example.com
https://chat.example.com/media
The favicon itself is publicly accessible and loads correctly when opened directly in the browser. Fluxer stores the configured URL successfully, but the browser blocks the request because the parent domain is not included in the generated img-src CSP.
  • 617554997-7678ad66-5c41-4e64-be34-4de6f573814d.png

    617554997-7678ad66-5c41-4e64-be34-4de6f573814d.png

    2560×1395 | 317 kB

  • 617554999-fde1f63a-90d7-4c23-8201-01292a73455a.png

    617554999-fde1f63a-90d7-4c23-8201-01292a73455a.png

    925×70 | 26 kB

  • 617554998-2debad44-c246-4e4d-9f0c-d9ca03bd5081.png

    617554998-2debad44-c246-4e4d-9f0c-d9ca03bd5081.png

    930×378 | 86 kB

  • 617555000-28d9a57d-a441-419a-ab60-cfc0f49a9de0.png

    617555000-28d9a57d-a441-419a-ab60-cfc0f49a9de0.png

    1490×767 | 78 kB

Comments

Sign in with Fluxer to comment and vote.

No comments yet.