| <?php |
|
|
| |
| |
| |
| |
| |
| |
|
|
| namespace Piwik\View; |
|
|
| use Piwik\Config; |
|
|
| |
| |
| |
| |
| class SecurityPolicy |
| { |
| |
| |
| |
| public const RULE_DEFAULT = "'self' 'unsafe-inline' 'unsafe-eval'"; |
| public const RULE_IMG_DEFAULT = "'self' 'unsafe-inline' 'unsafe-eval' data:"; |
| public const RULE_EMBEDDED_FRAME = "'self' 'unsafe-inline' 'unsafe-eval' data: https: http:"; |
|
|
| |
| |
| |
| |
| |
| |
| private $policies = array(); |
|
|
| private $cspEnabled; |
| private $reportOnly; |
|
|
| public function __construct(Config $config) |
| { |
| $this->policies['default-src'] = self::RULE_DEFAULT; |
| $this->policies['img-src'] = self::RULE_IMG_DEFAULT; |
|
|
| $generalConfig = $config->General; |
| $this->cspEnabled = $generalConfig['csp_enabled'] ?? true; |
| $this->reportOnly = $generalConfig['csp_report_only'] ?? false; |
| } |
|
|
| |
| |
| |
| |
| |
| public function addPolicy($directive, $value) |
| { |
| if (isset($this->policies[$directive])) { |
| $this->policies[$directive] .= ' ' . $value; |
| } else { |
| $this->policies[$directive] = $value; |
| } |
| } |
|
|
| |
| |
| |
| |
| |
| public function removeDirective($directive) |
| { |
| if (isset($this->policies[$directive])) { |
| unset($this->policies[$directive]); |
| } |
| } |
|
|
| |
| |
| |
| |
| |
| public function overridePolicy($directive, $value) |
| { |
| $this->policies[$directive] = $value; |
| } |
|
|
| |
| |
| |
| |
| |
| public function disable() |
| { |
| $this->cspEnabled = false; |
| } |
|
|
| |
| |
| |
| |
| |
| public function createHeaderString() |
| { |
| if (!$this->cspEnabled) { |
| return ''; |
| } |
|
|
| if ($this->reportOnly) { |
| $headerString = 'Content-Security-Policy-Report-Only: '; |
| } else { |
| $headerString = 'Content-Security-Policy: '; |
| } |
| foreach ($this->policies as $directive => $values) { |
| $headerString .= $directive . ' ' . $values . '; '; |
| } |
|
|
| return $headerString; |
| } |
|
|
| |
| |
| |
| |
| |
| |
| public function allowEmbedPage() |
| { |
| $this->overridePolicy('default-src', self::RULE_EMBEDDED_FRAME); |
| $this->overridePolicy('img-src', self::RULE_EMBEDDED_FRAME); |
| $this->addPolicy('script-src', self::RULE_DEFAULT); |
| } |
| } |
|
|