fix: recipe config cleanup, report-only CSP, logout redirect validation (#6124)
This commit is contained in:
1 parent
973631b7e8
commit
f8546ce0e0
27 files changed
+446
-75
No files matched your search
@@ -24,3 +24,12 @@ localhost/pacs -> Orthanc
|
||||
|
||||
|
||||
See [here](../../../docs/docs/deployment/nginx--image-archive.md) for more information about this recipe.
|
||||
|
||||
# Security notes
|
||||
|
||||
- CORS: earlier versions of this recipe set `Access-Control-Allow-Origin: *`
|
||||
on the `/pacs/` proxy. That default has been removed. The viewer is served
|
||||
by the same nginx as the proxy, so same-origin deployments need no CORS
|
||||
headers. If you host the viewer on a different origin, set that origin
|
||||
explicitly in `config/nginx.conf` - never `*` on an endpoint that serves
|
||||
PHI.
|
||||
@@ -32,6 +32,15 @@ http {
|
||||
gzip_comp_level 9;
|
||||
etag on;
|
||||
|
||||
# Content-Security-Policy: test in Report-Only mode first and watch the
|
||||
# browser console for violations before switching the header name to the
|
||||
# enforcing Content-Security-Policy. Note: nginx add_header does not merge
|
||||
# into a location that sets its own add_header - if you promote this to an
|
||||
# active header, re-declare it inside every location block that already
|
||||
# uses add_header (the /pacs/ proxy here does) or it will silently not
|
||||
# apply there.
|
||||
# add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self' https: blob:; worker-src 'self' blob:; object-src 'self' blob:; frame-src 'self' blob:; frame-ancestors 'none'; base-uri 'self'; form-action 'self'" always;
|
||||
|
||||
|
||||
# Reverse Proxy for `orthanc` APIs (including DICOMWeb)
|
||||
#
|
||||
@@ -47,17 +56,14 @@ http {
|
||||
expires 0;
|
||||
add_header Cache-Control private;
|
||||
|
||||
# Add CORS headers
|
||||
# Note: uncomment the following line to allow all domains to access the Orthanc APIs
|
||||
# You should actually only allow the domains you trust to access the APIs
|
||||
# add_header 'Access-Control-Allow-Origin' '*' always;
|
||||
# CORS: this recipe serves the viewer from this same nginx, so browser
|
||||
# requests to /pacs/ are same-origin and need NO CORS header at all.
|
||||
# If you host the viewer on a different origin, allow that origin
|
||||
# explicitly and only that origin - never use '*' on an endpoint that
|
||||
# serves PHI. Example:
|
||||
# add_header 'Access-Control-Allow-Origin' 'https://viewer.example.com' always;
|
||||
|
||||
proxy_pass http://orthanc:8042/;
|
||||
|
||||
# By default, this endpoint is protected by CORS (cross-origin-resource-sharing)
|
||||
# You can add headers to allow other domains to request this resource.
|
||||
# See the "Updating CORS Settings" example below
|
||||
add_header 'Access-Control-Allow-Origin' '*' always;
|
||||
}
|
||||
|
||||
|
||||
|
||||
Reference in new issue
Block a user