Canary desktop app CSP does not include the self-hosted FLUXER_DOMAIN

(#773) Bug Needs triage desktop self-hosting

Observed behaviour

This only affects the Canary Desktop App. No changes should be made to the web app or the regular frontend. The CSP adjustment should be implemented exclusively in the Canary Desktop App / its fluxer-app-proxy. File: /fluxer_app_proxy/src/csp.rs The CSP should read the FLUXER_DOMAIN environment variable at runtime and automatically add the configured domain to the required CSP directives. Example: FLUXER_DOMAIN=fluxer.example.com ↓ fluxer-app-proxy (Canary Desktop App) ↓ Content-Security-Policy ↓ https://fluxer.example.com/ Important:
  • The domain must be read from FLUXER_DOMAIN at runtime.
  • The change applies exclusively to the Canary Desktop App.
  • No frontend changes or custom frontend builds should be required.
  • When starting the self-hosted stack with FLUXER_DOMAIN=fluxer.example.com, the generated CSP must automatically include https://fluxer.example.com in the relevant directives.

Platform

macOS, Windows, Linux

4 comments

Sign in with Fluxer to comment and vote.
Comment by @ThesiiNCey
RexSystem 1 vote originally by @ThesiiNCey on GitHub OP
After making the change and rebuilding the Docker image, the desktop client worked without any issues for me.
Comment by @Crosus97
RexSystem 1 vote originally by @Crosus97 on GitHub
SAme from here image
  • 636750640-2a5475b0-0a9e-4b1d-9ea4-a0519fa23109.png

    636750640-2a5475b0-0a9e-4b1d-9ea4-a0519fa23109.png

    2559×1439 | 452 kB

Comment by @Crosus97
RexSystem 1 vote originally by @Crosus97 on GitHub
any news about this? the button disappear