From b02350d423120165fdbe76e1710a548075c52c5e Mon Sep 17 00:00:00 2001 From: maziggy Date: Sat, 2 May 2026 12:32:02 +0200 Subject: [PATCH] fix(security): allow iframe embedding from trusted origins via env var (#1191) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Bambuddy ships strict anti-clickjacking headers (X-Frame-Options: SAMEORIGIN + CSP frame-ancestors 'none') by default. Internet-exposed deployments need this; same-LAN HA Webpage-panel users do not, and SAMEORIGIN is port-strict so HA on :8123 + Bambuddy on :8000 always fails. azurusnova hit exactly that case. Add TRUSTED_FRAME_ORIGINS env var (comma-separated scheme://host[:port]). When set, drop X-Frame-Options entirely (modern browsers honor frame-ancestors and the legacy ALLOW-FROM syntax is deprecated / inconsistent across vendors) and emit "frame-ancestors 'self' " on every CSP-bearing route. Origin validation is strict: only http(s), no paths, no query/fragment, no wildcards. Bad entries get a warning and are dropped — startup never fails. Default behaviour (no env var) is unchanged: X-Frame-Options: SAMEORIGIN + frame-ancestors 'none', so existing Docker / bare-metal deployments are not affected. --- .env.example | 8 + CHANGELOG.md | 2 + backend/app/main.py | 88 +++++++++- .../integration/test_security_headers.py | 162 ++++++++++++++++++ 4 files changed, 253 insertions(+), 7 deletions(-) create mode 100644 backend/tests/integration/test_security_headers.py diff --git a/.env.example b/.env.example index b8df7014c..6527d4a34 100644 --- a/.env.example +++ b/.env.example @@ -16,3 +16,11 @@ LOG_TO_FILE=true # and these values override any database settings (read-only in UI) # HA_URL=http://supervisor/core # HA_TOKEN=your-long-lived-access-token + +# Trusted iframe origins (#1191) — comma-separated list of scheme://host[:port] +# origins permitted to embed Bambuddy via