fix(configuration): Harden dynamic datasource URL trust boundaries and credential handling. (#5963)

* fix(configuration): Harden dynamic datasource URL trust boundaries and credential handling.

* Remove testing configuration.

* Update policies for runtime ?url=... datasource loading.

* PR feedback.
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2026-04-21 11:55:14 -04:00
1 parent 51e6b35dbb
commit eede569a88
6 files changed
+334 -13

No files matched your search

+12
View File
@@ -251,6 +251,12 @@ window.config = {
configuration: {
friendlyName: 'dicomweb delegating proxy',
name: 'dicomwebproxy',
// Security controls for runtime ?url=... datasource loading:
// In authenticated environments, runtime ?url origins must be allowlisted:
// dangerouslyAllowedOriginsForAuthenticatedEnvironments: [
// 'https://config.example.com',
// 'http://localhost:5000',
// ],
},
},
{
@@ -259,6 +265,12 @@ window.config = {
configuration: {
friendlyName: 'dicom json',
name: 'json',
// Security controls for runtime ?url=... datasource loading:
// In authenticated environments, runtime ?url origins must be allowlisted:
// dangerouslyAllowedOriginsForAuthenticatedEnvironments: [
// 'https://config.example.com',
// 'http://localhost:5000',
// ],
},
},
{