Skip to content

Add CustomersDot to frame-src in CSP settings if set

Vitaly Slobodin requested to merge vs/add-customersdot-to-csp-framesrc into master

What does this MR do?

For local development we require to load CustomersDot via an iFrame but currently it's not possible because the local URL differs from the origin of GDK: gitlab.local:3000 vs localhost:5000. This MR adds CUSTOMER_PORTAL_URL to the frame-src directive if it was set in env.runit.

Screenshots (strongly suggested)

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

Does this MR contain changes to processing or storing of credentials or tokens, authorization and authentication methods or other items described in the security review guidelines? If not, then delete this Security section.

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Vitaly Slobodin

Merge request reports