Module: Gitlab::ContentSecurityPolicy::Directives

Defined in:
lib/gitlab/content_security_policy/directives.rb

Class Method Summary collapse

Class Method Details

.connect_srcObject



10
11
12
# File 'lib/gitlab/content_security_policy/directives.rb', line 10

def self.connect_src
  "'self'"
end

.frame_srcObject



14
15
16
17
18
# File 'lib/gitlab/content_security_policy/directives.rb', line 14

def self.frame_src
  base_urls = "https://www.google.com/recaptcha/ https://www.recaptcha.net/ https://www.googletagmanager.com/ns.html"

  ENV['O11Y_URL'].present? ? "#{base_urls} #{ENV['O11Y_URL']}" : base_urls
end

.script_srcObject



20
21
22
# File 'lib/gitlab/content_security_policy/directives.rb', line 20

def self.script_src
  "'strict-dynamic' 'self' 'unsafe-eval' https://www.google.com/recaptcha/ https://www.recaptcha.net"
end

.style_srcObject



24
25
26
# File 'lib/gitlab/content_security_policy/directives.rb', line 24

def self.style_src
  "'self' 'unsafe-inline'"
end

.worker_srcObject



28
29
30
# File 'lib/gitlab/content_security_policy/directives.rb', line 28

def self.worker_src
  "'self' #{Gitlab::Utils.append_path(Gitlab.config.gitlab.url, 'assets/')} blob: data:"
end