fix: explicitly set Content-Type for swagger static files
Some checks failed
CI / Build & Test (push) Has been cancelled
Some checks failed
CI / Build & Test (push) Has been cancelled
This commit is contained in:
parent
d26f5962ed
commit
10d3342f74
@ -3,8 +3,10 @@ package middleware
|
|||||||
import (
|
import (
|
||||||
"bufio"
|
"bufio"
|
||||||
"bytes"
|
"bytes"
|
||||||
|
"mime"
|
||||||
"net"
|
"net"
|
||||||
"net/http"
|
"net/http"
|
||||||
|
"path/filepath"
|
||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@ -12,8 +14,6 @@ import (
|
|||||||
"github.com/gin-gonic/gin"
|
"github.com/gin-gonic/gin"
|
||||||
)
|
)
|
||||||
|
|
||||||
// SwaggerHandler serves Swagger UI with relaxed CSP headers and MengStack
|
|
||||||
// branding CSS injected into swagger-ui.css.
|
|
||||||
func SwaggerHandler() gin.HandlerFunc {
|
func SwaggerHandler() gin.HandlerFunc {
|
||||||
return func(c *gin.Context) {
|
return func(c *gin.Context) {
|
||||||
rawPath := c.Request.URL.Path
|
rawPath := c.Request.URL.Path
|
||||||
@ -37,21 +37,28 @@ func SwaggerHandler() gin.HandlerFunc {
|
|||||||
|
|
||||||
c.Writer = underlying
|
c.Writer = underlying
|
||||||
|
|
||||||
c.Header("X-Content-Type-Options", "nosniff")
|
h := underlying.Header()
|
||||||
c.Header("X-Frame-Options", "DENY")
|
h.Set("X-Content-Type-Options", "nosniff")
|
||||||
c.Header("X-XSS-Protection", "1; mode=block")
|
h.Set("X-Frame-Options", "DENY")
|
||||||
c.Header("Referrer-Policy", "strict-origin-when-cross-origin")
|
h.Set("X-XSS-Protection", "1; mode=block")
|
||||||
c.Header("Content-Security-Policy", "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:")
|
h.Set("Referrer-Policy", "strict-origin-when-cross-origin")
|
||||||
|
h.Set("Content-Security-Policy", "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:")
|
||||||
|
|
||||||
if isCSS && crw.code == 200 && crw.buf.Len() > 0 {
|
if isCSS && crw.code == 200 && crw.buf.Len() > 0 {
|
||||||
body := append(crw.buf.Bytes(), []byte(brandingCSS)...)
|
body := append(crw.buf.Bytes(), []byte(brandingCSS)...)
|
||||||
c.Header("Content-Length", strconv.Itoa(len(body)))
|
h.Set("Content-Length", strconv.Itoa(len(body)))
|
||||||
c.Header("Content-Type", "text/css; charset=utf-8")
|
h.Set("Content-Type", "text/css; charset=utf-8")
|
||||||
|
underlying.WriteHeader(crw.code)
|
||||||
underlying.Write(body)
|
underlying.Write(body)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
if crw.buf.Len() > 0 {
|
if crw.buf.Len() > 0 {
|
||||||
|
ext := filepath.Ext(relPath)
|
||||||
|
if ct := mime.TypeByExtension(ext); ct != "" {
|
||||||
|
h.Set("Content-Type", ct)
|
||||||
|
}
|
||||||
|
h.Del("Content-Length")
|
||||||
underlying.WriteHeader(crw.code)
|
underlying.WriteHeader(crw.code)
|
||||||
underlying.Write(crw.buf.Bytes())
|
underlying.Write(crw.buf.Bytes())
|
||||||
return
|
return
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user