Files
bambuddy/backend
maziggy 07ef042729 fix(csp): allow http: iframes so Spoolman loads on HTTP LAN hosts (#1054)
The strict CSP shipped in 0.2.3b4 / 0.2.3.1 whitelisted only `https:`
  for `frame-src`, so the Filament tab's Spoolman iframe was blocked
  on the typical self-host setup where Spoolman runs on plain HTTP on
  a LAN. Reporter saw a blank Filament page with a brief Spoolman
  flash on reload and a browser-console CSP violation pointing at
  `http://<host>:7912/spool`.

  Allow `http:` as well, matching the `connect-src 'self' ws: wss:`
  pattern already used for WebSockets. `frame-ancestors 'none'` still
  prevents Bambuddy itself from being framed cross-origin, which is
  the protection that actually matters for clickjacking defense.
2026-04-21 09:18:25 +02:00
..
2025-11-28 10:23:59 +01:00