Class: SecureHeaders::ContentSecurityPolicy

Inherits:
Header
  • Object
show all
Includes:
Constants
Defined in:
lib/secure_headers/headers/content_security_policy.rb,
lib/secure_headers/headers/content_security_policy/script_hash_middleware.rb

Defined Under Namespace

Modules: Constants Classes: ScriptHashMiddleware

Constant Summary

Constants included from Constants

Constants::ALL_DIRECTIVES, Constants::CONFIG_KEY, Constants::DEFAULT_CSP_HEADER, Constants::DIRECTIVES, Constants::ENV_KEY, Constants::HEADER_NAME, Constants::OTHER

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(config = nil, options = {}) ⇒ ContentSecurityPolicy

options param contains :controller used for setting instance variables for nonces/hashes :ssl_request used to determine if http_additions should be used :ua the user agent (or just use Firefox/Chrome/MSIE/etc)

:report used to determine what :ssl_request, :ua, and :request_uri are set to



91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
# File 'lib/secure_headers/headers/content_security_policy.rb', line 91

def initialize(config=nil, options={})
  return unless config

  if options[:request]
    options = options.merge(self.class.options_from_request(options[:request]))
  end

  @controller = options[:controller]
  @ua = options[:ua]
  @ssl_request = !!options.delete(:ssl)
  @request_uri = options.delete(:request_uri)

  # Config values can be string, array, or lamdba values
  @config = config.inject({}) do |hash, (key, value)|
    config_val = value.respond_to?(:call) ? value.call(@controller) : value

    if DIRECTIVES.include?(key) # directives need to be normalized to arrays of strings
      config_val = config_val.split if config_val.is_a? String
      if config_val.is_a?(Array)
        config_val = config_val.map do |val|
          translate_dir_value(val)
        end.flatten.uniq
      end
    end

    hash[key] = config_val
    hash
  end

  @http_additions = @config.delete(:http_additions)
  @app_name = @config.delete(:app_name)
  @report_uri = @config.delete(:report_uri)
  @enforce = !!@config.delete(:enforce)
  @disable_img_src_data_uri = !!@config.delete(:disable_img_src_data_uri)
  @tag_report_uri = !!@config.delete(:tag_report_uri)
  @script_hashes = @config.delete(:script_hashes) || []

  add_script_hashes if @script_hashes.any?
end

Instance Attribute Details

#ssl_request ⇒ Object (readonly) Also known as: ssl_request?

Returns the value of attribute ssl_request.



41
42
43
# File 'lib/secure_headers/headers/content_security_policy.rb', line 41

def ssl_request
  @ssl_request
end

Class Method Details

.add_to_env(request, controller, config) ⇒ Object



53
54
55
56
57
58
59
60
# File 'lib/secure_headers/headers/content_security_policy.rb', line 53

def add_to_env(request, controller, config)
  set_nonce(controller)
  options = options_from_request(request).merge(:controller => controller)
  request.env[Constants::ENV_KEY] = {
    :config => config,
    :options => options,
  }
end

.from_json(*json_configs) ⇒ Object



166
167
168
169
170
171
172
173
174
# File 'lib/secure_headers/headers/content_security_policy.rb', line 166

def self.from_json(*json_configs)
  json_configs.inject({}) do |combined_config, one_config|
    one_config = one_config.gsub(/(\w+)-src/, "\\1_src")
    config = JSON.parse(one_config, :symbolize_names => true)
    combined_config.merge(config) do |_, lhs, rhs|
      lhs | rhs
    end
  end
end

.generate_nonce ⇒ Object



45
46
47
# File 'lib/secure_headers/headers/content_security_policy.rb', line 45

def generate_nonce
  SecureRandom.base64(32).chomp
end

.options_from_request(request) ⇒ Object



62
63
64
65
66
67
68
# File 'lib/secure_headers/headers/content_security_policy.rb', line 62

def options_from_request(request)
  {
    :ssl => request.ssl?,
    :ua => request.env['HTTP_USER_AGENT'],
    :request_uri => request_uri_from_request(request),
  }
end

.request_uri_from_request(request) ⇒ Object



70
71
72
73
74
75
76
77
78
# File 'lib/secure_headers/headers/content_security_policy.rb', line 70

def request_uri_from_request(request)
  if request.respond_to?(:original_url)
    # rails 3.1+
    request.original_url
  else
    # rails 2/3.0
    request.url
  end
end

.set_nonce(controller, nonce = generate_nonce) ⇒ Object



49
50
51
# File 'lib/secure_headers/headers/content_security_policy.rb', line 49

def set_nonce(controller, nonce = generate_nonce)
  controller.instance_variable_set(:@content_security_policy_nonce, nonce)
end

.symbol_to_hyphen_case(sym) ⇒ Object



80
81
82
# File 'lib/secure_headers/headers/content_security_policy.rb', line 80

def symbol_to_hyphen_case sym
  sym.to_s.gsub('_', '-')
end

Instance Method Details

#name ⇒ Object

Returns the name to use for the header. Either "Content-Security-Policy" or "Content-Security-Policy-Report-Only"



142
143
144
145
146
147
148
# File 'lib/secure_headers/headers/content_security_policy.rb', line 142

def name
  base = HEADER_NAME
  if !@enforce
    base += "-Report-Only"
  end
  base
end

#nonce ⇒ Object

Return or initialize the nonce value used for this header. If a reference to a controller is passed in the config, this method will check if a nonce has already been set and use it.



135
136
137
# File 'lib/secure_headers/headers/content_security_policy.rb', line 135

def nonce
  @nonce ||= @controller.instance_variable_get(:@content_security_policy_nonce) || self.class.generate_nonce
end

#to_json ⇒ Object



161
162
163
164
# File 'lib/secure_headers/headers/content_security_policy.rb', line 161

def to_json
  build_value
  @config.to_json.gsub(/(\w+)_src/, "\\1-src")
end

#value ⇒ Object

Return the value of the CSP header



152
153
154
155
156
157
158
159
# File 'lib/secure_headers/headers/content_security_policy.rb', line 152

def value
  return @config if @config.is_a?(String)
  if @config
    build_value
  else
    DEFAULT_CSP_HEADER
  end
end