diff --git a/CHANGELOG.md b/CHANGELOG.md index 5746c01408..59481e7c67 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - Fixed the missing mapping for Aland Islands in the country weightings of the _Financial Modeling Prep_ service - Fixed the net performance percentage of date ranges in the portfolio performance calculation by weighting the average investment by the number of days between the chart dates - Fixed the start date of calendar year date ranges in the portfolio performance calculation +- Fixed an issue where the Content Security Policy in HTTP security headers blocked the status check of the Ghostfolio data provider when `ENABLE_FEATURE_SECURITY_HEADERS` was enabled (experimental) ## 3.80.2 - 2026-10-06 diff --git a/apps/api/src/helper/security-headers.helper.spec.ts b/apps/api/src/helper/security-headers.helper.spec.ts index 1d5f0ac03f..231054e59e 100644 --- a/apps/api/src/helper/security-headers.helper.spec.ts +++ b/apps/api/src/helper/security-headers.helper.spec.ts @@ -52,6 +52,12 @@ describe('getHelmetOptions', () => { ); }); + it('should allow connections to ghostfol.io for the status check of the Ghostfolio data provider', () => { + expect(headers.get('content-security-policy')).toContain( + "connect-src 'self' https://ghostfol.io" + ); + }); + it('should not upgrade insecure requests', () => { expect(headers.get('content-security-policy')).not.toContain( 'upgrade-insecure-requests' diff --git a/apps/api/src/helper/security-headers.helper.ts b/apps/api/src/helper/security-headers.helper.ts index f983bdc900..f9631ec292 100644 --- a/apps/api/src/helper/security-headers.helper.ts +++ b/apps/api/src/helper/security-headers.helper.ts @@ -25,6 +25,7 @@ export function getHelmetOptions({ return { contentSecurityPolicy: { directives: { + connectSrc: ["'self'", 'https://ghostfol.io'], // Allow connections to ghostfol.io for the status check of the Ghostfolio data provider scriptSrc: ["'self'", "'unsafe-inline'"], // Allow inline scripts scriptSrcAttr: ["'self'", "'unsafe-inline'"], // Allow inline event handlers styleSrc: ["'self'", "'unsafe-inline'"], // Allow inline styles