Skip to content

Commit 28f6873

Browse files
authored
Adjust sensitive headers (#3559)
1 parent e0ca2e4 commit 28f6873

File tree

1 file changed

+11
-2
lines changed

1 file changed

+11
-2
lines changed

src/server/configs/opensource/common.ts

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,8 @@ import {
88
DL_CONTEXT_HEADER,
99
Language,
1010
PALETTE_ID,
11+
US_DYNAMIC_MASTER_TOKEN_HEADER,
12+
US_MASTER_TOKEN_HEADER,
1113
isTrueArg,
1214
} from '../../../shared';
1315
import {UserRole} from '../../../shared/components/auth/constants/role';
@@ -19,6 +21,13 @@ import controlDashChartTemplate from '../shared/control-dash-chart-template';
1921
import datalensChartTemplate from '../shared/datalens-chart-template';
2022
import qlChartTemplate from '../shared/ql-chart-template';
2123

24+
const sensitiveHeaders = [
25+
CSP_HEADER,
26+
CSP_REPORT_TO_HEADER,
27+
US_DYNAMIC_MASTER_TOKEN_HEADER,
28+
US_MASTER_TOKEN_HEADER,
29+
];
30+
2231
export default {
2332
// DATALENS MODE
2433
serviceName: SERVICE_NAME_DATALENS,
@@ -213,8 +222,8 @@ export default {
213222
},
214223
defaultColorPaletteId: PALETTE_ID.DEFAULT_20,
215224

216-
appSensitiveKeys: [CSP_HEADER, CSP_REPORT_TO_HEADER],
217-
appSensitiveHeaders: [CSP_HEADER, CSP_REPORT_TO_HEADER],
225+
appSensitiveKeys: sensitiveHeaders,
226+
appSensitiveHeaders: sensitiveHeaders,
218227

219228
// auth
220229
isAuthEnabled: isTrueArg(process.env.AUTH_ENABLED),

0 commit comments

Comments
 (0)