модуль ActionController::ContentSecurityPolicy::ClassMethods
Открытые методы экземпляра
# File actionpack/lib/action_controller/metal/content_security_policy.rb, line 40
def content_security_policy(enabled = true, **options, &block)
before_action(options) do
if block_given?
policy = current_content_security_policy
instance_exec(policy, &block)
request.content_security_policy = policy
end
unless enabled
request.content_security_policy = nil
end
end
end Переопределяет части глобально настроенного заголовка Content-Security-Policy:
class PostsController < ApplicationController
content_security_policy do |policy|
policy.base_uri "https://www.example.com"
end
end
Параметры можно передавать аналогично before_action. Например, передайте only: :index, чтобы переопределить заголовок только для действия index:
class PostsController < ApplicationController
content_security_policy(only: :index) do |policy|
policy.default_src :self, :https
end
end
Передайте false, чтобы удалить заголовок Content-Security-Policy:
class PostsController < ApplicationController content_security_policy false, only: :index end
# File actionpack/lib/action_controller/metal/content_security_policy.rb, line 66
def content_security_policy_report_only(report_only = true, **options)
before_action(options) do
request.content_security_policy_report_only = report_only
end
end Переопределяет глобально настроенный заголовок Content-Security-Policy-Report-Only:
class PostsController < ApplicationController content_security_policy_report_only only: :index end
Передайте false, чтобы удалить заголовок Content-Security-Policy-Report-Only:
class PostsController < ApplicationController content_security_policy_report_only false, only: :index end
© 2004–2021 David Heinemeier Hansson
Licensed under the MIT License.