Files
bambuddy/.env.example
T
maziggy b02350d423 fix(security): allow iframe embedding from trusted origins via env var (#1191)
Bambuddy ships strict anti-clickjacking headers (X-Frame-Options:
  SAMEORIGIN + CSP frame-ancestors 'none') by default. Internet-exposed
  deployments need this; same-LAN HA Webpage-panel users do not, and
  SAMEORIGIN is port-strict so HA on :8123 + Bambuddy on :8000 always
  fails. azurusnova hit exactly that case.

  Add TRUSTED_FRAME_ORIGINS env var (comma-separated scheme://host[:port]).
  When set, drop X-Frame-Options entirely (modern browsers honor
  frame-ancestors and the legacy ALLOW-FROM syntax is deprecated /
  inconsistent across vendors) and emit "frame-ancestors 'self' <list>"
  on every CSP-bearing route. Origin validation is strict: only http(s),
  no paths, no query/fragment, no wildcards. Bad entries get a warning
  and are dropped — startup never fails.

  Default behaviour (no env var) is unchanged: X-Frame-Options:
  SAMEORIGIN + frame-ancestors 'none', so existing Docker / bare-metal
  deployments are not affected.
2026-05-02 12:32:02 +02:00

27 lines
1.1 KiB
Bash

# BambuTrack Environment Configuration
# Copy this file to .env and adjust values as needed
# Debug mode (true = DEBUG logging, false = production with INFO logging)
DEBUG=true
# Log level (only used when DEBUG=false)
# Options: DEBUG, INFO, WARNING, ERROR
LOG_LEVEL=INFO
# Enable file logging (logs written to logs/bambutrack.log)
LOG_TO_FILE=true
# Home Assistant Integration (for HA Add-on deployments)
# When both HA_URL and HA_TOKEN are set, Home Assistant integration is automatically enabled
# and these values override any database settings (read-only in UI)
# HA_URL=http://supervisor/core
# HA_TOKEN=your-long-lived-access-token
# Trusted iframe origins (#1191) — comma-separated list of scheme://host[:port]
# origins permitted to embed Bambuddy via <iframe>. Defaults to empty (strict:
# only same-origin embedding allowed). Set this to your Home Assistant origin
# when using the HA Webpage dashboard panel, since HA on port 8123 and Bambuddy
# on port 8000 are different origins to the browser. Wildcards, paths, and
# non-http(s) schemes are rejected at startup with a warning.
# TRUSTED_FRAME_ORIGINS=http://homeassistant.local:8123