mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 11:12:35 +02:00
Bambuddy ships strict anti-clickjacking headers (X-Frame-Options: SAMEORIGIN + CSP frame-ancestors 'none') by default. Internet-exposed deployments need this; same-LAN HA Webpage-panel users do not, and SAMEORIGIN is port-strict so HA on :8123 + Bambuddy on :8000 always fails. azurusnova hit exactly that case. Add TRUSTED_FRAME_ORIGINS env var (comma-separated scheme://host[:port]). When set, drop X-Frame-Options entirely (modern browsers honor frame-ancestors and the legacy ALLOW-FROM syntax is deprecated / inconsistent across vendors) and emit "frame-ancestors 'self' <list>" on every CSP-bearing route. Origin validation is strict: only http(s), no paths, no query/fragment, no wildcards. Bad entries get a warning and are dropped — startup never fails. Default behaviour (no env var) is unchanged: X-Frame-Options: SAMEORIGIN + frame-ancestors 'none', so existing Docker / bare-metal deployments are not affected.
27 lines
1.1 KiB
Bash
27 lines
1.1 KiB
Bash
# BambuTrack Environment Configuration
|
|
# Copy this file to .env and adjust values as needed
|
|
|
|
# Debug mode (true = DEBUG logging, false = production with INFO logging)
|
|
DEBUG=true
|
|
|
|
# Log level (only used when DEBUG=false)
|
|
# Options: DEBUG, INFO, WARNING, ERROR
|
|
LOG_LEVEL=INFO
|
|
|
|
# Enable file logging (logs written to logs/bambutrack.log)
|
|
LOG_TO_FILE=true
|
|
|
|
# Home Assistant Integration (for HA Add-on deployments)
|
|
# When both HA_URL and HA_TOKEN are set, Home Assistant integration is automatically enabled
|
|
# and these values override any database settings (read-only in UI)
|
|
# HA_URL=http://supervisor/core
|
|
# HA_TOKEN=your-long-lived-access-token
|
|
|
|
# Trusted iframe origins (#1191) — comma-separated list of scheme://host[:port]
|
|
# origins permitted to embed Bambuddy via <iframe>. Defaults to empty (strict:
|
|
# only same-origin embedding allowed). Set this to your Home Assistant origin
|
|
# when using the HA Webpage dashboard panel, since HA on port 8123 and Bambuddy
|
|
# on port 8000 are different origins to the browser. Wildcards, paths, and
|
|
# non-http(s) schemes are rejected at startup with a warning.
|
|
# TRUSTED_FRAME_ORIGINS=http://homeassistant.local:8123
|