Edit history

Earlier versions of Canary desktop app CSP does not include the self-hosted FLUXER_DOMAIN, newest first.

Current version | Edited by Rex
Changes
Removed: CSP issue with self-hosted setupAdded: Canary desktop app CSP does not include the self-hosted FLUXER_DOMAIN
Show

Canary desktop app CSP does not include the self-hosted FLUXER_DOMAIN

Observed behaviour

This only affects the Canary Desktop App. No changes should be made to the web app or the regular frontend. The CSP adjustment should be implemented exclusively in the Canary Desktop App / its fluxer-app-proxy. File: /fluxer_app_proxy/src/csp.rs The CSP should read the FLUXER_DOMAIN environment variable at runtime and automatically add the configured domain to the required CSP directives. Example: FLUXER_DOMAIN=fluxer.example.com ↓ fluxer-app-proxy (Canary Desktop App) ↓ Content-Security-Policy ↓ https://fluxer.example.com/ Important:
  • The domain must be read from FLUXER_DOMAIN at runtime.
  • The change applies exclusively to the Canary Desktop App.
  • No frontend changes or custom frontend builds should be required.
  • When starting the self-hosted stack with FLUXER_DOMAIN=fluxer.example.com, the generated CSP must automatically include https://fluxer.example.com in the relevant directives.

Platform

macOS, Windows, Linux

Original by Rex
Show

CSP issue with self-hosted setup

Observed behaviour

This only affects the Canary Desktop App. No changes should be made to the web app or the regular frontend. The CSP adjustment should be implemented exclusively in the Canary Desktop App / its fluxer-app-proxy. File: /fluxer_app_proxy/src/csp.rs The CSP should read the FLUXER_DOMAIN environment variable at runtime and automatically add the configured domain to the required CSP directives. Example: FLUXER_DOMAIN=fluxer.example.com ↓ fluxer-app-proxy (Canary Desktop App) ↓ Content-Security-Policy ↓ https://fluxer.example.com/ Important:
  • The domain must be read from FLUXER_DOMAIN at runtime.
  • The change applies exclusively to the Canary Desktop App.
  • No frontend changes or custom frontend builds should be required.
  • When starting the self-hosted stack with FLUXER_DOMAIN=fluxer.example.com, the generated CSP must automatically include https://fluxer.example.com in the relevant directives.

Platform

macOS, Windows, Linux