fix(security): allow iframe embedding from trusted origins via env var (#1191)

Bambuddy ships strict anti-clickjacking headers (X-Frame-Options:
  SAMEORIGIN + CSP frame-ancestors 'none') by default. Internet-exposed
  deployments need this; same-LAN HA Webpage-panel users do not, and
  SAMEORIGIN is port-strict so HA on :8123 + Bambuddy on :8000 always
  fails. azurusnova hit exactly that case.

  Add TRUSTED_FRAME_ORIGINS env var (comma-separated scheme://host[:port]).
  When set, drop X-Frame-Options entirely (modern browsers honor
  frame-ancestors and the legacy ALLOW-FROM syntax is deprecated /
  inconsistent across vendors) and emit "frame-ancestors 'self' <list>"
  on every CSP-bearing route. Origin validation is strict: only http(s),
  no paths, no query/fragment, no wildcards. Bad entries get a warning
  and are dropped — startup never fails.

  Default behaviour (no env var) is unchanged: X-Frame-Options:
  SAMEORIGIN + frame-ancestors 'none', so existing Docker / bare-metal
  deployments are not affected.
This commit is contained in:
maziggy
2026-05-02 12:32:02 +02:00
parent 31577b8d2b
commit b02350d423
4 changed files with 253 additions and 7 deletions
+8
View File
@@ -16,3 +16,11 @@ LOG_TO_FILE=true
# and these values override any database settings (read-only in UI)
# HA_URL=http://supervisor/core
# HA_TOKEN=your-long-lived-access-token
# Trusted iframe origins (#1191) — comma-separated list of scheme://host[:port]
# origins permitted to embed Bambuddy via <iframe>. Defaults to empty (strict:
# only same-origin embedding allowed). Set this to your Home Assistant origin
# when using the HA Webpage dashboard panel, since HA on port 8123 and Bambuddy
# on port 8000 are different origins to the browser. Wildcards, paths, and
# non-http(s) schemes are rejected at startup with a warning.
# TRUSTED_FRAME_ORIGINS=http://homeassistant.local:8123