fix: separate swagger handler and CSS branding middleware
Some checks failed
CI / Build & Test (push) Has been cancelled
Some checks failed
CI / Build & Test (push) Has been cancelled
This commit is contained in:
parent
df30ea5c33
commit
434dbcc7fa
@ -94,7 +94,7 @@ func newEngine(
|
||||
upgradeHandler := upgrade.NewHandler()
|
||||
r.GET("/api/upgrade/check", upgradeHandler.Check)
|
||||
|
||||
r.GET("/swagger/*any", middleware.SwaggerHandler())
|
||||
r.GET("/swagger/*any", middleware.SwaggerCSSBranding(), middleware.SwaggerHandler())
|
||||
|
||||
tenantResolver := tenant.NewResolver(cfg.Tenant)
|
||||
|
||||
|
||||
@ -3,10 +3,8 @@ package middleware
|
||||
import (
|
||||
"bufio"
|
||||
"bytes"
|
||||
"mime"
|
||||
"net"
|
||||
"net/http"
|
||||
"path/filepath"
|
||||
"strconv"
|
||||
"strings"
|
||||
|
||||
@ -16,14 +14,13 @@ import (
|
||||
)
|
||||
|
||||
func SwaggerHandler() gin.HandlerFunc {
|
||||
wrapHandler := ginSwagger.WrapHandler(swaggerFiles.Handler)
|
||||
return ginSwagger.WrapHandler(swaggerFiles.Handler)
|
||||
}
|
||||
|
||||
func SwaggerCSSBranding() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
relPath := strings.TrimPrefix(c.Request.URL.Path, "/swagger")
|
||||
isCSS := strings.HasSuffix(relPath, "swagger-ui.css")
|
||||
|
||||
if !isCSS {
|
||||
wrapHandler(c)
|
||||
if !strings.HasSuffix(c.Request.URL.Path, "swagger-ui.css") {
|
||||
c.Next()
|
||||
return
|
||||
}
|
||||
|
||||
@ -34,19 +31,13 @@ func SwaggerHandler() gin.HandlerFunc {
|
||||
}
|
||||
c.Writer = crw
|
||||
|
||||
wrapHandler(c)
|
||||
c.Next()
|
||||
|
||||
c.Writer = underlying
|
||||
|
||||
h := underlying.Header()
|
||||
h.Set("X-Content-Type-Options", "nosniff")
|
||||
h.Set("X-Frame-Options", "DENY")
|
||||
h.Set("X-XSS-Protection", "1; mode=block")
|
||||
h.Set("Referrer-Policy", "strict-origin-when-cross-origin")
|
||||
h.Set("Content-Security-Policy", "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:")
|
||||
|
||||
if crw.code == 200 && crw.buf.Len() > 0 {
|
||||
body := append(crw.buf.Bytes(), []byte(brandingCSS)...)
|
||||
h := underlying.Header()
|
||||
h.Set("Content-Length", strconv.Itoa(len(body)))
|
||||
h.Set("Content-Type", "text/css; charset=utf-8")
|
||||
underlying.WriteHeader(crw.code)
|
||||
@ -55,10 +46,6 @@ func SwaggerHandler() gin.HandlerFunc {
|
||||
}
|
||||
|
||||
if crw.buf.Len() > 0 {
|
||||
ext := filepath.Ext(relPath)
|
||||
if ct := mime.TypeByExtension(ext); ct != "" {
|
||||
h.Set("Content-Type", ct)
|
||||
}
|
||||
underlying.WriteHeader(crw.code)
|
||||
underlying.Write(crw.buf.Bytes())
|
||||
return
|
||||
|
||||
Loading…
Reference in New Issue
Block a user