Skip to content

- redoc CPS issue #1930

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 29, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions kairon/actions/server.py
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
from loguru import logger as logging
from time import time
import copy

from fastapi import FastAPI
from fastapi import Request, status
Expand Down Expand Up @@ -131,6 +132,13 @@ async def add_secure_headers(request: Request, call_next):
response.headers["Access-Control-Allow-Origin"] = (
requested_origin if requested_origin is not None else allowed_origins[0]
)
if request.url.path == "/redoc":
custom_csp = copy.deepcopy(csp)
custom_csp.worker_src("blob:")
secure_headers.csp = custom_csp
secure_headers.framework.fastapi(response)
secure_headers.csp = csp

return response


Expand Down
7 changes: 7 additions & 0 deletions kairon/api/app/main.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
import copy
from fastapi import FastAPI, Request
from fastapi.exceptions import RequestValidationError
from fastapi.middleware.cors import CORSMiddleware
Expand Down Expand Up @@ -98,6 +99,12 @@ async def add_secure_headers(request: Request, call_next):
response.headers['Cross-Origin-Resource-Policy'] = 'same-origin'
requested_origin = request.headers.get("origin")
response.headers["Access-Control-Allow-Origin"] = requested_origin if requested_origin is not None else allowed_origins[0]
if request.url.path == "/redoc":
custom_csp = copy.deepcopy(csp)
custom_csp.worker_src("blob:")
secure_headers.csp = custom_csp
secure_headers.framework.fastapi(response)
secure_headers.csp = csp
return response


Expand Down
7 changes: 7 additions & 0 deletions kairon/chat/server.py
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
from time import time
import copy

from fastapi import FastAPI, Request
from fastapi.exceptions import RequestValidationError
Expand Down Expand Up @@ -107,6 +108,12 @@ async def add_secure_headers(request: Request, call_next):
logger.info(
f"request path={request.url.path} completed_in={formatted_process_time}ms status_code={response.status_code}"
)
if request.url.path == "/redoc":
custom_csp = copy.deepcopy(csp)
custom_csp.worker_src("blob:")
secure_headers.csp = custom_csp
secure_headers.framework.fastapi(response)
secure_headers.csp = csp
return response


Expand Down
7 changes: 7 additions & 0 deletions kairon/events/server.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
import copy
from typing import Text

from fastapi import FastAPI, Request, Path, Query
Expand Down Expand Up @@ -86,6 +87,12 @@ async def add_secure_headers(request: Request, call_next):
response.headers["Access-Control-Allow-Origin"] = requested_origin if requested_origin else allowed_origins[0]
response.headers['Cross-Origin-Resource-Policy'] = 'same-origin'
response.headers['Content-Type'] = 'application/json'
if request.url.path == "/redoc":
custom_csp = copy.deepcopy(csp)
custom_csp.worker_src("blob:")
secure_headers.csp = custom_csp
secure_headers.framework.fastapi(response)
secure_headers.csp = csp
return response


Expand Down
25 changes: 25 additions & 0 deletions tests/integration_test/services_test.py
Original file line number Diff line number Diff line change
Expand Up @@ -30549,3 +30549,28 @@ def test_leave_non_existent_bot_1():
assert actual["message"] == "Access to bot is denied"
assert actual["error_code"] == 422
assert not actual["success"]



def test_redoc_headers():
response = client.get("/redoc")
assert response.status_code == 200
assert response.headers == {
"content-length": "498",
"content-type": "text/html; charset=utf-8",
"content-encoding": "gzip",
"vary": "Accept-Encoding",
"server": "Secure",
"strict-transport-security": "includeSubDomains; preload; max-age=31536000",
"x-frame-options": "SAMEORIGIN",
"x-xss-protection": "0",
"x-content-type-options": "nosniff",
"content-security-policy": "default-src 'self'; frame-ancestors 'self'; form-action 'self'; base-uri 'self'; connect-src 'self'; frame-src 'self'; style-src 'self' https: 'unsafe-inline'; img-src 'self' https:; script-src 'self' https: 'unsafe-inline'; worker-src blob:",
"referrer-policy": "no-referrer",
"cache-control": "must-revalidate",
"permissions-policy": "accelerometer=(), autoplay=(), camera=(), document-domain=(), encrypted-media=(), fullscreen=(), vibrate=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), sync-xhr=(), usb=()",
"cross-origin-embedder-policy": "require-corp",
"cross-origin-opener-policy": "same-origin",
"cross-origin-resource-policy": "same-origin",
"access-control-allow-origin": "*"
}
Loading