Skip to content

Commit 95f3b61

Browse files
committed
also add frame-src
1 parent b3ac3ee commit 95f3b61

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

coderd/httpmw/csp.go

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,7 @@ const (
3939
CSPDirectiveFormAction CSPFetchDirective = "form-action"
4040
CSPDirectiveMediaSrc CSPFetchDirective = "media-src"
4141
CSPFrameAncestors CSPFetchDirective = "frame-ancestors"
42+
CSPFrameSource CSPFetchDirective = "frame-src"
4243
CSPDirectiveWorkerSrc CSPFetchDirective = "worker-src"
4344
)
4445

@@ -100,6 +101,7 @@ func CSPHeaders(experiments codersdk.Experiments, telemetry bool, websocketHosts
100101
// AI tasks use iframe embeds of local apps.
101102
// TODO: Handle region domains too, not just path based apps
102103
cspSrcs.Append(CSPFrameAncestors, `'self'`)
104+
cspSrcs.Append(CSPFrameSource, `'self'`)
103105
} else {
104106
cspSrcs.Append(CSPFrameAncestors, `'none'`)
105107
}

0 commit comments

Comments
 (0)