Browse Source

Bugfix/content security policy for Ghostfolio data provider (#8082)

* Fix content security policy for Ghostfolio data provider

* Update changelog
pull/8085/head
Thomas Kaul 23 hours ago
committed by GitHub
parent
commit
2254f7989c
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 1
      CHANGELOG.md
  2. 6
      apps/api/src/helper/security-headers.helper.spec.ts
  3. 1
      apps/api/src/helper/security-headers.helper.ts

1
CHANGELOG.md

@ -19,6 +19,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- Fixed the missing mapping for Aland Islands in the country weightings of the _Financial Modeling Prep_ service
- Fixed the net performance percentage of date ranges in the portfolio performance calculation by weighting the average investment by the number of days between the chart dates
- Fixed the start date of calendar year date ranges in the portfolio performance calculation
- Fixed an issue where the Content Security Policy in HTTP security headers blocked the status check of the Ghostfolio data provider when `ENABLE_FEATURE_SECURITY_HEADERS` was enabled (experimental)
## 3.80.2 - 2026-10-06

6
apps/api/src/helper/security-headers.helper.spec.ts

@ -52,6 +52,12 @@ describe('getHelmetOptions', () => {
);
});
it('should allow connections to ghostfol.io for the status check of the Ghostfolio data provider', () => {
expect(headers.get('content-security-policy')).toContain(
"connect-src 'self' https://ghostfol.io"
);
});
it('should not upgrade insecure requests', () => {
expect(headers.get('content-security-policy')).not.toContain(
'upgrade-insecure-requests'

1
apps/api/src/helper/security-headers.helper.ts

@ -25,6 +25,7 @@ export function getHelmetOptions({
return {
contentSecurityPolicy: {
directives: {
connectSrc: ["'self'", 'https://ghostfol.io'], // Allow connections to ghostfol.io for the status check of the Ghostfolio data provider
scriptSrc: ["'self'", "'unsafe-inline'"], // Allow inline scripts
scriptSrcAttr: ["'self'", "'unsafe-inline'"], // Allow inline event handlers
styleSrc: ["'self'", "'unsafe-inline'"], // Allow inline styles

Loading…
Cancel
Save