Observed behaviour
This only affects the Canary Desktop App. No changes should be made to the web app or the regular frontend.
The CSP adjustment should be implemented exclusively in the Canary Desktop App / its
fluxer-app-proxy.
File:
/fluxer_app_proxy/src/csp.rs
The CSP should read the FLUXER_DOMAIN environment variable at runtime and automatically add the configured domain to the required CSP directives.
Example:
FLUXER_DOMAIN=fluxer.example.com
↓
fluxer-app-proxy (Canary Desktop App)
↓
Content-Security-Policy
↓
https://fluxer.example.com/
Important:
- The domain must be read from
FLUXER_DOMAINat runtime. - The change applies exclusively to the Canary Desktop App.
- No frontend changes or custom frontend builds should be required.
- When starting the self-hosted stack with
FLUXER_DOMAIN=fluxer.example.com, the generated CSP must automatically includehttps://fluxer.example.comin the relevant directives.
Platform
macOS, Windows, Linux