Skip to content

feat(proxy): accept lists and globs for the CSP config file locations - #3686

Open
dschmidt wants to merge 1 commit into
mainfrom
feat/proxy-csp-config-globs
Open

dschmidt wants to merge 1 commit into
mainfrom
feat/proxy-csp-config-globs

Conversation

@dschmidt

@dschmidt dschmidt commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

PROXY_CSP_CONFIG_FILE_LOCATION and PROXY_CSP_CONFIG_FILE_OVERRIDE_LOCATION accept a list, and each element can be a path or a glob. That way every web app can ship its own csp.yaml and the proxy merges them, e.g. /etc/opencloud/csp.yaml,/web/apps/*/csp.yaml.

 LoadCSPConfig
-  LOCATION:          merge(default CSP, file)
-  OVERRIDE_LOCATION: file
+  LOCATION:          merge(default CSP, files...)
+  OVERRIDE_LOCATION: merge(files...), LOCATION is ignored as before

files is the list of that variable with globs expanded. The list order is the merge order. Only the matches of a single glob have no given order, they are merged sorted by name.

LOCATION OVERRIDE_LOCATION
glob without matches skipped skipped
plain path, file missing fatal, as before fatal, as before
no file at all default CSP fatal

The fields change from string to []string. A single path keeps working from env and from a yaml scalar. The merge semantics are unchanged.

loadCSPConfig now uses its own gookit instance instead of the global one, because a second call in the same process panicked. The new tests need that.

This enables opencloud-eu/web-extensions#621

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant