mirror of
https://github.com/zitadel/zitadel.git
synced 2025-08-11 17:48:07 +00:00
middleware change
This commit is contained in:
@@ -56,18 +56,16 @@ export async function middleware(request: NextRequest) {
|
|||||||
securitySettings = await loadSecuritySettings(request);
|
securitySettings = await loadSecuritySettings(request);
|
||||||
|
|
||||||
if (securitySettings?.embeddedIframe?.enabled) {
|
if (securitySettings?.embeddedIframe?.enabled) {
|
||||||
const responseHeaders = new Headers();
|
const response = NextResponse.next({
|
||||||
|
request: { headers: requestHeaders },
|
||||||
|
});
|
||||||
|
|
||||||
responseHeaders.set(
|
response.headers.set(
|
||||||
"Content-Security-Policy",
|
"Content-Security-Policy",
|
||||||
`${DEFAULT_CSP} frame-ancestors ${securitySettings.embeddedIframe.allowedOrigins.join(" ")};`,
|
`${DEFAULT_CSP} frame-ancestors ${securitySettings.embeddedIframe.allowedOrigins.join(" ")};`,
|
||||||
);
|
);
|
||||||
responseHeaders.delete("X-Frame-Options");
|
response.headers.delete("X-Frame-Options");
|
||||||
|
return response;
|
||||||
return NextResponse.next({
|
|
||||||
request: { headers: requestHeaders },
|
|
||||||
headers: responseHeaders,
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user