mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
fix(security): allow iframe embedding from trusted origins via env var (#1191)
Bambuddy ships strict anti-clickjacking headers (X-Frame-Options: SAMEORIGIN + CSP frame-ancestors 'none') by default. Internet-exposed deployments need this; same-LAN HA Webpage-panel users do not, and SAMEORIGIN is port-strict so HA on :8123 + Bambuddy on :8000 always fails. azurusnova hit exactly that case. Add TRUSTED_FRAME_ORIGINS env var (comma-separated scheme://host[:port]). When set, drop X-Frame-Options entirely (modern browsers honor frame-ancestors and the legacy ALLOW-FROM syntax is deprecated / inconsistent across vendors) and emit "frame-ancestors 'self' <list>" on every CSP-bearing route. Origin validation is strict: only http(s), no paths, no query/fragment, no wildcards. Bad entries get a warning and are dropped — startup never fails. Default behaviour (no env var) is unchanged: X-Frame-Options: SAMEORIGIN + frame-ancestors 'none', so existing Docker / bare-metal deployments are not affected.
This commit is contained in:
@@ -16,3 +16,11 @@ LOG_TO_FILE=true
|
||||
# and these values override any database settings (read-only in UI)
|
||||
# HA_URL=http://supervisor/core
|
||||
# HA_TOKEN=your-long-lived-access-token
|
||||
|
||||
# Trusted iframe origins (#1191) — comma-separated list of scheme://host[:port]
|
||||
# origins permitted to embed Bambuddy via <iframe>. Defaults to empty (strict:
|
||||
# only same-origin embedding allowed). Set this to your Home Assistant origin
|
||||
# when using the HA Webpage dashboard panel, since HA on port 8123 and Bambuddy
|
||||
# on port 8000 are different origins to the browser. Wildcards, paths, and
|
||||
# non-http(s) schemes are rejected at startup with a warning.
|
||||
# TRUSTED_FRAME_ORIGINS=http://homeassistant.local:8123
|
||||
|
||||
Reference in New Issue
Block a user