Module: SecureHeaders
- Included in:
- ActionController::Base
- Defined in:
- lib/secure_headers.rb,
lib/secure_headers/padrino.rb,
lib/secure_headers/railtie.rb,
lib/secure_headers/middleware.rb,
lib/secure_headers/view_helper.rb,
lib/secure_headers/configuration.rb,
lib/secure_headers/headers/public_key_pins.rb,
lib/secure_headers/headers/x_frame_options.rb,
lib/secure_headers/headers/x_xss_protection.rb,
lib/secure_headers/headers/x_download_options.rb,
lib/secure_headers/headers/x_content_type_options.rb,
lib/secure_headers/headers/content_security_policy.rb,
lib/secure_headers/headers/strict_transport_security.rb,
lib/secure_headers/headers/x_permitted_cross_domain_policies.rb
Overview
All headers (except for hpkp) have a default value. Provide SecureHeaders::OPT_OUT or ":optout_of_protection" as a config value to disable a given header
Defined Under Namespace
Modules: Padrino, ViewHelpers Classes: Configuration, ContentSecurityPolicy, ContentSecurityPolicyConfigError, Middleware, PublicKeyPins, PublicKeyPinsConfigError, Railtie, STSConfigError, StrictTransportSecurity, XContentTypeOptions, XContentTypeOptionsConfigError, XDOConfigError, XDownloadOptions, XFOConfigError, XFrameOptions, XPCDPConfigError, XPermittedCrossDomainPolicies, XXssProtection, XXssProtectionConfigError
Constant Summary collapse
- OPT_OUT =
:opt_out_of_protection- SECURE_HEADERS_CONFIG =
"secure_headers_request_config".freeze
- NONCE_KEY =
"secure_headers_content_security_policy_nonce".freeze
- HTTPS =
"https".freeze
- CSP =
ContentSecurityPolicy- ALL_HEADER_CLASSES =
[ ContentSecurityPolicy, StrictTransportSecurity, PublicKeyPins, XContentTypeOptions, XDownloadOptions, XFrameOptions, XPermittedCrossDomainPolicies, XXssProtection ].freeze
- ALL_HEADERS_BESIDES_CSP =
(ALL_HEADER_CLASSES - [CSP]).freeze
- HTTP_HEADER_CLASSES =
Headers set on http requests (excludes STS and HPKP)
(ALL_HEADER_CLASSES - [StrictTransportSecurity, PublicKeyPins]).freeze
Class Method Summary collapse
-
.append_content_security_policy_directives(request, additions) ⇒ Object
Public: appends source values to the current configuration.
-
.content_security_policy_script_nonce(request) ⇒ Object
Public: gets or creates a nonce for CSP.
-
.content_security_policy_style_nonce(request) ⇒ Object
Public: gets or creates a nonce for CSP.
-
.header_hash_for(request) ⇒ Object
Public: Builds the hash of headers that should be applied base on the request.
-
.opt_out_of_all_protection(request) ⇒ Object
Public: opts out of setting all headers by telling secure_headers to use the NOOP configuration.
-
.opt_out_of_header(request, header_key) ⇒ Object
Public: opts out of setting a given header by creating a temporary config and setting the given headers config to OPT_OUT.
-
.override_content_security_policy_directives(request, additions) ⇒ Object
Public: override a given set of directives for the current request.
-
.override_x_frame_options(request, value) ⇒ Object
Public: override X-Frame-Options settings for this request.
-
.use_secure_headers_override(request, name) ⇒ Object
Public: specify which named override will be used for this request.
Instance Method Summary collapse
- #append_content_security_policy_directives(additions) ⇒ Object
- #content_security_policy_script_nonce ⇒ Object
- #content_security_policy_style_nonce ⇒ Object
- #opt_out_of_header(header_key) ⇒ Object
- #override_content_security_policy_directives(additions) ⇒ Object
- #override_x_frame_options(value) ⇒ Object
-
#use_secure_headers_override(name) ⇒ Object
These methods are mixed into controllers and delegate to the class method with the same name.
Class Method Details
.append_content_security_policy_directives(request, additions) ⇒ Object
Public: appends source values to the current configuration. If no value is set for a given directive, the value will be merged with the default-src value. If a value exists for the given directive, the values will be combined.
additions - a hash containing directives. e.g. script_src: %w(another-host.com)
67 68 69 70 71 72 73 74 |
# File 'lib/secure_headers.rb', line 67 def append_content_security_policy_directives(request, additions) config = config_for(request) unless CSP.idempotent_additions?(config.csp, additions) config = config.dup config.csp = CSP.combine_policies(config.csp, additions) override_secure_headers_request_config(request, config) end end |
.content_security_policy_script_nonce(request) ⇒ Object
Public: gets or creates a nonce for CSP.
The nonce will be added to script_src
Returns the nonce
139 140 141 |
# File 'lib/secure_headers.rb', line 139 def content_security_policy_script_nonce(request) content_security_policy_nonce(request, CSP::SCRIPT_SRC) end |
.content_security_policy_style_nonce(request) ⇒ Object
Public: gets or creates a nonce for CSP.
The nonce will be added to style_src
Returns the nonce
148 149 150 |
# File 'lib/secure_headers.rb', line 148 def content_security_policy_style_nonce(request) content_security_policy_nonce(request, CSP::STYLE_SRC) end |
.header_hash_for(request) ⇒ Object
Public: Builds the hash of headers that should be applied base on the request.
StrictTransportSecurity and PublicKeyPins are not applied to http requests. See #config_for to determine which config is used for a given request.
Returns a hash of header names => header values. The value
returned is meant to be merged into the header value from @app.call(env)
in Rack middleware.
110 111 112 113 114 115 116 117 118 119 120 |
# File 'lib/secure_headers.rb', line 110 def header_hash_for(request) config = config_for(request) headers = if cached_headers = config.cached_headers use_cached_headers(cached_headers, request) else build_headers(config, request) end headers end |
.opt_out_of_all_protection(request) ⇒ Object
Public: opts out of setting all headers by telling secure_headers to use the NOOP configuration.
97 98 99 |
# File 'lib/secure_headers.rb', line 97 def opt_out_of_all_protection(request) use_secure_headers_override(request, Configuration::NOOP_CONFIGURATION) end |
.opt_out_of_header(request, header_key) ⇒ Object
Public: opts out of setting a given header by creating a temporary config and setting the given headers config to OPT_OUT.
89 90 91 92 93 |
# File 'lib/secure_headers.rb', line 89 def opt_out_of_header(request, header_key) config = config_for(request).dup config.send("#{header_key}=", OPT_OUT) override_secure_headers_request_config(request, config) end |
.override_content_security_policy_directives(request, additions) ⇒ Object
Public: override a given set of directives for the current request. If a value already exists for a given directive, it will be overridden.
If CSP was previously OPT_OUT, a new blank policy is used.
additions - a hash containing directives. e.g. script_src: %w(another-host.com)
49 50 51 52 53 54 55 56 57 58 59 |
# File 'lib/secure_headers.rb', line 49 def override_content_security_policy_directives(request, additions) config = config_for(request) unless CSP.idempotent_additions?(config.csp, additions) config = config.dup if config.csp == OPT_OUT config.csp = {} end config.csp.merge!(additions) override_secure_headers_request_config(request, config) end end |
.override_x_frame_options(request, value) ⇒ Object
Public: override X-Frame-Options settings for this request.
value - deny, sameorigin, or allowall
Returns the current config
81 82 83 84 85 |
# File 'lib/secure_headers.rb', line 81 def (request, value) default_config = config_for(request).dup default_config. = value override_secure_headers_request_config(request, default_config) end |
.use_secure_headers_override(request, name) ⇒ Object
Public: specify which named override will be used for this request. Raises an argument error if no named override exists.
name - the name of the previously configured override.
126 127 128 129 130 131 132 |
# File 'lib/secure_headers.rb', line 126 def use_secure_headers_override(request, name) if config = Configuration.get(name) override_secure_headers_request_config(request, config) else raise ArgumentError.new("no override by the name of #{name} has been configured") end end |
Instance Method Details
#append_content_security_policy_directives(additions) ⇒ Object
281 282 283 |
# File 'lib/secure_headers.rb', line 281 def append_content_security_policy_directives(additions) SecureHeaders.append_content_security_policy_directives(request, additions) end |
#content_security_policy_script_nonce ⇒ Object
269 270 271 |
# File 'lib/secure_headers.rb', line 269 def content_security_policy_script_nonce SecureHeaders.content_security_policy_script_nonce(request) end |
#content_security_policy_style_nonce ⇒ Object
273 274 275 |
# File 'lib/secure_headers.rb', line 273 def content_security_policy_style_nonce SecureHeaders.content_security_policy_style_nonce(request) end |
#opt_out_of_header(header_key) ⇒ Object
277 278 279 |
# File 'lib/secure_headers.rb', line 277 def opt_out_of_header(header_key) SecureHeaders.opt_out_of_header(request, header_key) end |
#override_content_security_policy_directives(additions) ⇒ Object
285 286 287 |
# File 'lib/secure_headers.rb', line 285 def override_content_security_policy_directives(additions) SecureHeaders.override_content_security_policy_directives(request, additions) end |
#override_x_frame_options(value) ⇒ Object
289 290 291 |
# File 'lib/secure_headers.rb', line 289 def (value) SecureHeaders.(request, value) end |
#use_secure_headers_override(name) ⇒ Object
These methods are mixed into controllers and delegate to the class method with the same name.
265 266 267 |
# File 'lib/secure_headers.rb', line 265 def use_secure_headers_override(name) SecureHeaders.use_secure_headers_override(request, name) end |