fix: explicitly set Content-Type for swagger static files
Some checks failed
CI / Build & Test (push) Has been cancelled

This commit is contained in:
MengStack Dev 2026-10-03 04:11:34 +08:00
parent d26f5962ed
commit 10d3342f74

View File

@ -3,8 +3,10 @@ package middleware
import ( import (
"bufio" "bufio"
"bytes" "bytes"
"mime"
"net" "net"
"net/http" "net/http"
"path/filepath"
"strconv" "strconv"
"strings" "strings"
@ -12,8 +14,6 @@ import (
"github.com/gin-gonic/gin" "github.com/gin-gonic/gin"
) )
// SwaggerHandler serves Swagger UI with relaxed CSP headers and MengStack
// branding CSS injected into swagger-ui.css.
func SwaggerHandler() gin.HandlerFunc { func SwaggerHandler() gin.HandlerFunc {
return func(c *gin.Context) { return func(c *gin.Context) {
rawPath := c.Request.URL.Path rawPath := c.Request.URL.Path
@ -37,21 +37,28 @@ func SwaggerHandler() gin.HandlerFunc {
c.Writer = underlying c.Writer = underlying
c.Header("X-Content-Type-Options", "nosniff") h := underlying.Header()
c.Header("X-Frame-Options", "DENY") h.Set("X-Content-Type-Options", "nosniff")
c.Header("X-XSS-Protection", "1; mode=block") h.Set("X-Frame-Options", "DENY")
c.Header("Referrer-Policy", "strict-origin-when-cross-origin") h.Set("X-XSS-Protection", "1; mode=block")
c.Header("Content-Security-Policy", "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:") h.Set("Referrer-Policy", "strict-origin-when-cross-origin")
h.Set("Content-Security-Policy", "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:")
if isCSS && crw.code == 200 && crw.buf.Len() > 0 { if isCSS && crw.code == 200 && crw.buf.Len() > 0 {
body := append(crw.buf.Bytes(), []byte(brandingCSS)...) body := append(crw.buf.Bytes(), []byte(brandingCSS)...)
c.Header("Content-Length", strconv.Itoa(len(body))) h.Set("Content-Length", strconv.Itoa(len(body)))
c.Header("Content-Type", "text/css; charset=utf-8") h.Set("Content-Type", "text/css; charset=utf-8")
underlying.WriteHeader(crw.code)
underlying.Write(body) underlying.Write(body)
return return
} }
if crw.buf.Len() > 0 { if crw.buf.Len() > 0 {
ext := filepath.Ext(relPath)
if ct := mime.TypeByExtension(ext); ct != "" {
h.Set("Content-Type", ct)
}
h.Del("Content-Length")
underlying.WriteHeader(crw.code) underlying.WriteHeader(crw.code)
underlying.Write(crw.buf.Bytes()) underlying.Write(crw.buf.Bytes())
return return