api-docs: use hardcoded script sha for oauth2-redirect.html CSP

Signed-off-by: Patrik Oldsberg <poldsberg@gmail.com>
This commit is contained in:
Patrik Oldsberg
2021-11-30 13:41:37 +01:00
committed by GitHub
parent fb7a0bdeac
commit f0adfda527
+6 -10
View File
@@ -160,17 +160,13 @@ by this plugin.
Grab a copy of [oauth2-redirect.html](https://github.com/swagger-api/swagger-ui/blob/master/dist/oauth2-redirect.html)
and put it in the `app/public/` directory in order to enable Swagger UI to complete this redirection.
This also may require you to adjust `Content Security Policy` header settings of your backstage application. So javascript on `oauth2-redirect.html` can be executed.
This also may require you to adjust `Content Security Policy` header settings of your Backstage application, so that the script in `oauth2-redirect.html` can be executed. Since the script is static we can add the hash of it directly to our CSP policy, which we do by adding the following to the `csp` section of the app configuration:
There are two steps:
1. Open `oauth2-redirect.html` for editing and add `nonce` to the `script` tag. Like this
```
<script nonce="oauth2-redirect">
```
2. Now adjust backstage configuration, `backend.csp` section and add there new property:
```
script-src: ["'self'", "'nonce-oauth2-redirect'", "'unsafe-eval'"]
```
```yaml
script-src:
- "'self'"
- "'sha256-GeDavzSZ8O71Jggf/pQkKbt52dfZkrdNMQ3e+Ox+AkI='" # oauth2-redirect.html
```
#### Configuring your OAuth2 Client