api-docs: use hardcoded script sha for oauth2-redirect.html CSP
Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
This commit is contained in:
@@ -160,17 +160,13 @@ by this plugin.
|
||||
Grab a copy of [oauth2-redirect.html](https://github.com/swagger-api/swagger-ui/blob/master/dist/oauth2-redirect.html)
|
||||
and put it in the `app/public/` directory in order to enable Swagger UI to complete this redirection.
|
||||
|
||||
This also may require you to adjust `Content Security Policy` header settings of your backstage application. So javascript on `oauth2-redirect.html` can be executed.
|
||||
This also may require you to adjust `Content Security Policy` header settings of your Backstage application, so that the script in `oauth2-redirect.html` can be executed. Since the script is static we can add the hash of it directly to our CSP policy, which we do by adding the following to the `csp` section of the app configuration:
|
||||
|
||||
There are two steps:
|
||||
1. Open `oauth2-redirect.html` for editing and add `nonce` to the `script` tag. Like this
|
||||
```
|
||||
<script nonce="oauth2-redirect">
|
||||
```
|
||||
2. Now adjust backstage configuration, `backend.csp` section and add there new property:
|
||||
```
|
||||
script-src: ["'self'", "'nonce-oauth2-redirect'", "'unsafe-eval'"]
|
||||
```
|
||||
```yaml
|
||||
script-src:
|
||||
- "'self'"
|
||||
- "'sha256-GeDavzSZ8O71Jggf/pQkKbt52dfZkrdNMQ3e+Ox+AkI='" # oauth2-redirect.html
|
||||
```
|
||||
|
||||
#### Configuring your OAuth2 Client
|
||||
|
||||
|
||||
Reference in New Issue
Block a user