discourse/lib/validators/csp_script_src_validator.rb
Kelv 60d5170587
DEV: add validation on content_security_policy_script_src site setting (#27564)
* DEV: add validation on content_security_policy_script_src site setting
2024-06-21 17:00:22 +08:00

23 lines
461 B
Ruby

# frozen_string_literal: true
class CspScriptSrcValidator
VALID_SOURCE_REGEX =
/
(?:\A'unsafe-eval'\z)|
(?:\A'wasm-unsafe-eval'\z)|
(?:\A'sha(?:256|384|512)-[A-Za-z0-9+\/\-_]+={0,2}'\z)
/x
def initialize(opts = {})
@opts = opts
end
def valid_value?(values)
values.split("|").all? { _1.match? VALID_SOURCE_REGEX }
end
def error_message
I18n.t("site_settings.errors.invalid_csp_script_src")
end
end