Class: SecureHeaders::Configuration

Inherits:
Object
  • Object
show all
Defined in:
lib/secure_headers/configuration.rb

Defined Under Namespace

Classes: IllegalPolicyModificationError, NotYetConfiguredError

Constant Summary collapse

DEFAULT_CONFIG =
:default
NOOP_CONFIGURATION =
"secure_headers_noop_config"
HASH_CONFIG_FILE =
ENV["secure_headers_generated_hashes_file"] || "config/secure_headers_generated_hashes.yml"

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(&block) ⇒ Configuration

Returns a new instance of Configuration.



118
119
120
121
122
# File 'lib/secure_headers/configuration.rb', line 118

def initialize(&block)
  self.hpkp = OPT_OUT
  self.csp = self.class.send(:deep_copy, CSP::DEFAULT_CONFIG)
  instance_eval &block if block_given?
end

Instance Attribute Details

#cached_headers ⇒ Object

Returns the value of attribute cached_headers.



109
110
111
# File 'lib/secure_headers/configuration.rb', line 109

def cached_headers
  @cached_headers
end

#cookies ⇒ Object

Returns the value of attribute cookies.



109
110
111
# File 'lib/secure_headers/configuration.rb', line 109

def cookies
  @cookies
end

#csp ⇒ Object

Returns the value of attribute csp.



109
110
111
# File 'lib/secure_headers/configuration.rb', line 109

def csp
  @csp
end

#dynamic_csp ⇒ Object

Returns the value of attribute dynamic_csp.



109
110
111
# File 'lib/secure_headers/configuration.rb', line 109

def dynamic_csp
  @dynamic_csp
end

#hpkp=(value) ⇒ Object (writeonly)

Sets the attribute hpkp

Parameters:

  • value —

    the value to set the attribute hpkp to.



105
106
107
# File 'lib/secure_headers/configuration.rb', line 105

def hpkp=(value)
  @hpkp = value
end

#hsts=(value) ⇒ Object (writeonly)

Sets the attribute hsts

Parameters:

  • value —

    the value to set the attribute hsts to.



105
106
107
# File 'lib/secure_headers/configuration.rb', line 105

def hsts=(value)
  @hsts = value
end

#x_content_type_options=(value) ⇒ Object (writeonly)

Sets the attribute x_content_type_options

Parameters:

  • value —

    the value to set the attribute x_content_type_options to.



105
106
107
# File 'lib/secure_headers/configuration.rb', line 105

def x_content_type_options=(value)
  @x_content_type_options = value
end

#x_download_options=(value) ⇒ Object (writeonly)

Sets the attribute x_download_options

Parameters:

  • value —

    the value to set the attribute x_download_options to.



105
106
107
# File 'lib/secure_headers/configuration.rb', line 105

def x_download_options=(value)
  @x_download_options = value
end

#x_frame_options=(value) ⇒ Object (writeonly)

Sets the attribute x_frame_options

Parameters:

  • value —

    the value to set the attribute x_frame_options to.



105
106
107
# File 'lib/secure_headers/configuration.rb', line 105

def x_frame_options=(value)
  @x_frame_options = value
end

#x_permitted_cross_domain_policies=(value) ⇒ Object (writeonly)

Sets the attribute x_permitted_cross_domain_policies

Parameters:

  • value —

    the value to set the attribute x_permitted_cross_domain_policies to.



105
106
107
# File 'lib/secure_headers/configuration.rb', line 105

def x_permitted_cross_domain_policies=(value)
  @x_permitted_cross_domain_policies = value
end

#x_xss_protection=(value) ⇒ Object (writeonly)

Sets the attribute x_xss_protection

Parameters:

  • value —

    the value to set the attribute x_xss_protection to.



105
106
107
# File 'lib/secure_headers/configuration.rb', line 105

def x_xss_protection=(value)
  @x_xss_protection = value
end

Class Method Details

.default(&block) ⇒ Object Also known as: configure

Public: Set the global default configuration.

Optionally supply a block to override the defaults set by this library.

Returns the newly created config.



15
16
17
18
19
# File 'lib/secure_headers/configuration.rb', line 15

def default(&block)
  config = new(&block)
  add_noop_configuration
  add_configuration(DEFAULT_CONFIG, config)
end

.get(name = DEFAULT_CONFIG) ⇒ Object

Public: retrieve a global configuration object

Returns the configuration with a given name or raises a NotYetConfiguredError if default has not been called.



42
43
44
45
46
47
# File 'lib/secure_headers/configuration.rb', line 42

def get(name = DEFAULT_CONFIG)
  if @configurations.nil?
    raise NotYetConfiguredError, "Default policy not yet supplied"
  end
  @configurations[name]
end

.override(name, base = DEFAULT_CONFIG, &block) ⇒ Object

Public: create a named configuration that overrides the default config.

name - use an idenfier for the override config. base - override another existing config, or override the default config if no value is supplied.

Returns: the newly created config



29
30
31
32
33
34
35
36
# File 'lib/secure_headers/configuration.rb', line 29

def override(name, base = DEFAULT_CONFIG, &block)
  unless get(base)
    raise NotYetConfiguredError, "#{base} policy not yet supplied"
  end
  override = @configurations[base].dup
  override.instance_eval &block if block_given?
  add_configuration(name, override)
end

Instance Method Details

#current_csp ⇒ Object



166
167
168
# File 'lib/secure_headers/configuration.rb', line 166

def current_csp
  @dynamic_csp || @csp
end

#dup ⇒ Object

Public: copy everything but the cached headers

Returns a deep-dup'd copy of this configuration.



127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
# File 'lib/secure_headers/configuration.rb', line 127

def dup
  copy = self.class.new
  copy.cookies = @cookies
  copy.csp = self.class.send(:deep_copy_if_hash, @csp)
  copy.dynamic_csp = self.class.send(:deep_copy_if_hash, @dynamic_csp)
  copy.cached_headers = self.class.send(:deep_copy_if_hash, @cached_headers)
  copy.x_content_type_options = @x_content_type_options
  copy.hsts = @hsts
  copy.x_frame_options = @x_frame_options
  copy.x_xss_protection = @x_xss_protection
  copy.x_download_options = @x_download_options
  copy.x_permitted_cross_domain_policies = @x_permitted_cross_domain_policies
  copy.hpkp = @hpkp
  copy
end

#opt_out(header) ⇒ Object



143
144
145
146
147
148
149
# File 'lib/secure_headers/configuration.rb', line 143

def opt_out(header)
  send("#{header}=", OPT_OUT)
  if header == CSP::CONFIG_KEY
    dynamic_csp = OPT_OUT
  end
  self.cached_headers.delete(header)
end

#rebuild_csp_header_cache!(user_agent) ⇒ Object

Public: generated cached headers for a specific user agent.



157
158
159
160
161
162
163
164
# File 'lib/secure_headers/configuration.rb', line 157

def rebuild_csp_header_cache!(user_agent)
  self.cached_headers[CSP::CONFIG_KEY] = {}
  unless current_csp == OPT_OUT
    user_agent = UserAgent.parse(user_agent)
    variation = CSP.ua_to_variation(user_agent)
    self.cached_headers[CSP::CONFIG_KEY][variation] = CSP.make_header(current_csp, user_agent)
  end
end

#secure_cookies=(secure_cookies) ⇒ Object



187
188
189
190
# File 'lib/secure_headers/configuration.rb', line 187

def secure_cookies=(secure_cookies)
  Kernel.warn "#{Kernel.caller.first}: [DEPRECATION] `#secure_cookies=` is deprecated. Please use `#cookies=` to configure secure cookies instead."
  @cookies = (@cookies || {}).merge(secure: secure_cookies)
end

#update_x_frame_options(value) ⇒ Object



151
152
153
154
# File 'lib/secure_headers/configuration.rb', line 151

def update_x_frame_options(value)
  @x_frame_options = value
  self.cached_headers[XFrameOptions::CONFIG_KEY] = XFrameOptions.make_header(value)
end

#validate_config! ⇒ Object

Public: validates all configurations values.

Raises various configuration errors if any invalid config is detected.

Returns nothing



175
176
177
178
179
180
181
182
183
184
185
# File 'lib/secure_headers/configuration.rb', line 175

def validate_config!
  StrictTransportSecurity.validate_config!(@hsts)
  ContentSecurityPolicy.validate_config!(@csp)
  XFrameOptions.validate_config!(@x_frame_options)
  XContentTypeOptions.validate_config!(@x_content_type_options)
  XXssProtection.validate_config!(@x_xss_protection)
  XDownloadOptions.validate_config!(@x_download_options)
  XPermittedCrossDomainPolicies.validate_config!(@x_permitted_cross_domain_policies)
  PublicKeyPins.validate_config!(@hpkp)
  Cookie.validate_config!(@cookies)
end