diff --git a/Sense/server/app/sense/liveview/http.go b/Sense/server/app/sense/liveview/http.go index 1e0c444..af8930f 100644 --- a/Sense/server/app/sense/liveview/http.go +++ b/Sense/server/app/sense/liveview/http.go @@ -61,6 +61,10 @@ func (m *Module) player(w http.ResponseWriter, r *http.Request) { } w.Header().Set("Content-Type", "text/html; charset=utf-8") w.Header().Set("Cache-Control", "no-store") - w.Header().Set("Content-Security-Policy", "default-src 'none'; frame-src http: https:; style-src 'unsafe-inline'") + // This endpoint is the authenticated, same-origin wrapper loaded by the + // live-view page. Keep the global DENY policy everywhere else, and allow + // only Sense itself to embed this wrapper. + w.Header().Set("X-Frame-Options", "SAMEORIGIN") + w.Header().Set("Content-Security-Policy", "default-src 'none'; frame-ancestors 'self'; frame-src http: https:; style-src 'unsafe-inline'") _ = playerTemplate.Execute(w, target) } diff --git a/Sense/server/app/sense/liveview/http_test.go b/Sense/server/app/sense/liveview/http_test.go new file mode 100644 index 0000000..96a05e9 --- /dev/null +++ b/Sense/server/app/sense/liveview/http_test.go @@ -0,0 +1,39 @@ +package liveview + +import ( + "context" + "net/http" + "net/http/httptest" + "strings" + "testing" + "time" + + "yovision.local/sense/app/sense/media" +) + +func TestPlayerAllowsOnlySameOriginEmbedding(t *testing.T) { + service, err := NewService("http://127.0.0.1:8889", time.Minute) + if err != nil { + t.Fatal(err) + } + route := media.Route{ID: "device:main", Path: "sense_device_main", Desired: "running", Actual: "ready"} + service.route = func(context.Context, string) (media.Route, error) { return route, nil } + service.refresh = func(context.Context, string) (media.Route, error) { return route, nil } + service.sessions["view_test"] = Session{ID: "view_test", RouteID: route.ID, ExpiresAt: time.Now().Add(time.Minute)} + + req := httptest.NewRequest(http.MethodGet, "/api/v1/liveview/sessions/view_test/player", nil) + req.SetPathValue("id", "view_test") + res := httptest.NewRecorder() + NewModule(service).player(res, req) + + if res.Code != http.StatusOK { + t.Fatalf("status = %d", res.Code) + } + if got := res.Header().Get("X-Frame-Options"); got != "SAMEORIGIN" { + t.Fatalf("X-Frame-Options = %q", got) + } + csp := res.Header().Get("Content-Security-Policy") + if !strings.Contains(csp, "frame-ancestors 'self'") { + t.Fatalf("Content-Security-Policy = %q", csp) + } +}