mirror of
https://github.com/Ylianst/MeshCentral.git
synced 2025-03-31 01:33:39 -04:00
Use x-forwarded-host first to fill connect-src
This commit is contained in:
parent
5bd361f4eb
commit
4f4d20649a
@ -4888,7 +4888,7 @@ module.exports.CreateWebServer = function (parent, db, args, certificates) {
|
|||||||
} else {
|
} else {
|
||||||
// Use default security headers
|
// Use default security headers
|
||||||
var geourl = (domain.geolocation ? ' *.openstreetmap.org' : '');
|
var geourl = (domain.geolocation ? ' *.openstreetmap.org' : '');
|
||||||
var selfurl = (' wss://' + req.headers.host);
|
var selfurl = req.headers['x-forwarded-host'] ? (' wss://' + req.headers['x-forwarded-host']) : (' wss://' + req.headers.host);
|
||||||
var headers = {
|
var headers = {
|
||||||
'Referrer-Policy': 'no-referrer',
|
'Referrer-Policy': 'no-referrer',
|
||||||
'X-XSS-Protection': '1; mode=block',
|
'X-XSS-Protection': '1; mode=block',
|
||||||
|
Loading…
x
Reference in New Issue
Block a user