diff options
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/app.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/app.py | 17 |
1 files changed, 16 insertions, 1 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/app.py b/packages/meshbay-hub/src/meshbay_hub/app.py index 2daa55b..7b187df 100644 --- a/packages/meshbay-hub/src/meshbay_hub/app.py +++ b/packages/meshbay-hub/src/meshbay_hub/app.py @@ -154,7 +154,22 @@ def create_app(cfg: HubConfig | None = None) -> FastAPI: response.headers.setdefault("Content-Security-Policy", CSP) response.headers.setdefault("X-Content-Type-Options", "nosniff") response.headers.setdefault("Referrer-Policy", "strict-origin-when-cross-origin") - response.headers.setdefault("X-Frame-Options", "DENY") + # SAMEORIGIN, matching `frame-ancestors 'self'` in the CSP above. + # + # The two say the same thing to different generations of browser, and + # they were saying different things: CSP allowed this origin to frame + # itself, this header forbade all framing. The spec says a browser must + # ignore X-Frame-Options when the CSP carries frame-ancestors — but + # relying on that while shipping a header that contradicts our own + # policy is asking to be surprised, and we were: the streamed download + # (a hidden iframe onto `/_mbdl/<id>`, the only way to write a large + # file to disk on Firefox and Safari) stayed blocked after the CSP was + # fixed, and this header was why it looked like the fix had not worked. + # + # No foreign origin may frame this page under either spelling. That is + # the property; DENY was one notch stricter than the property needed and + # broke a feature to get there. + response.headers.setdefault("X-Frame-Options", "SAMEORIGIN") return response # Routers (webapp last — catches / before API routes) |