fix: recipe config cleanup, report-only CSP, logout redirect validation (#6124)

This commit is contained in:
Alireza authored and GitHub committed 2026-07-07 13:18:46 -04:00
1 parent 973631b7e8
commit f8546ce0e0
27 files changed
+446 -75

No files matched your search

@@ -24,3 +24,12 @@ localhost/pacs -> Orthanc
See [here](../../../docs/docs/deployment/nginx--image-archive.md) for more information about this recipe.
# Security notes
- CORS: earlier versions of this recipe set `Access-Control-Allow-Origin: *`
on the `/pacs/` proxy. That default has been removed. The viewer is served
by the same nginx as the proxy, so same-origin deployments need no CORS
headers. If you host the viewer on a different origin, set that origin
explicitly in `config/nginx.conf` - never `*` on an endpoint that serves
PHI.
@@ -32,6 +32,15 @@ http {
gzip_comp_level 9;
etag on;
# Content-Security-Policy: test in Report-Only mode first and watch the
# browser console for violations before switching the header name to the
# enforcing Content-Security-Policy. Note: nginx add_header does not merge
# into a location that sets its own add_header - if you promote this to an
# active header, re-declare it inside every location block that already
# uses add_header (the /pacs/ proxy here does) or it will silently not
# apply there.
# add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self' https: blob:; worker-src 'self' blob:; object-src 'self' blob:; frame-src 'self' blob:; frame-ancestors 'none'; base-uri 'self'; form-action 'self'" always;
# Reverse Proxy for `orthanc` APIs (including DICOMWeb)
#
@@ -47,17 +56,14 @@ http {
expires 0;
add_header Cache-Control private;
# Add CORS headers
# Note: uncomment the following line to allow all domains to access the Orthanc APIs
# You should actually only allow the domains you trust to access the APIs
# add_header 'Access-Control-Allow-Origin' '*' always;
# CORS: this recipe serves the viewer from this same nginx, so browser
# requests to /pacs/ are same-origin and need NO CORS header at all.
# If you host the viewer on a different origin, allow that origin
# explicitly and only that origin - never use '*' on an endpoint that
# serves PHI. Example:
# add_header 'Access-Control-Allow-Origin' 'https://viewer.example.com' always;
proxy_pass http://orthanc:8042/;
# By default, this endpoint is protected by CORS (cross-origin-resource-sharing)
# You can add headers to allow other domains to request this resource.
# See the "Updating CORS Settings" example below
add_header 'Access-Control-Allow-Origin' '*' always;
}