Commit graph

7 commits

Author SHA1 Message Date
Molly Struve
d6449cab26
[deploy] Bug Fix:Comment out content security policy (#10192) 2020-09-03 13:30:10 -05:00
rhymes
f49ca8909a
[deploy] Revert "Enable CSP in report only mode and use Honeybadger to track violations (#10155)" (#10191)
This reverts commit 1df3e96652.
2020-09-03 12:43:11 -05:00
rhymes
1df3e96652
[deploy] Enable CSP in report only mode and use Honeybadger to track violations (#10155) 2020-09-03 18:45:31 +02:00
Ben Halpern
0efcc7f47f
[deploy] Add initial content security policy into codebase (to avoid reliance on edge configuration) (#10144)
* Initial secure header functionality

* Add unsafe-inline to csp

* Secure cookies

* Add connect-src

* Only run secure header config in prod (for now)

* Change prod check to within default

* Change from secure_headers to rails config

* Wrap behind production check
2020-09-01 20:32:13 -04:00
Dmitry Maksyoma
be07697d6d
Adapt dev env to run on a remote box (#8232)
* Adapt dev env to run on a remote box

* webpack-dev-server ignores CLI arguments, so switched to environment
  variables.
* Dynamically determine remote webpack host via APP_DOMAIN environment
  variable, defined in application.yml.
* Setup content security policy to allow connecting to webpack on a
  remote box, defined by APP_DOMAIN environment variable.

* Make Webpacker listen on 0.0.0.0

* Account for APP_DOMAIN port

* Add support for URI scheme and tests

* Fix a spec by disabling a Rubocop linter
2020-06-18 13:01:49 +02:00
rhymes
1112cbf316
[deploy] Update webpacker configuration (#8004) 2020-05-25 12:03:18 -04:00
rhymes
3a53d5797e Upgrade Rails to 5.2.3 (#1408) 2019-04-03 13:08:59 -04:00