Skip to content

Commit 6dabafe

Browse files
committed
chore: adjust sidekiq bypass
O bypass é seguro porque o /sidekiq ja e protegido pelo Rack::Auth::Basic e ninguem chega nos assets sem autenticar primeiro. O default-src 'none' e correto para os endpoints JSON da API, mas nao faz sentido para uma UI web
1 parent 30cb782 commit 6dabafe

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

lib/middleware/security_headers.rb

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,8 @@ def initialize(app)
3030

3131
def call(env)
3232
status, headers, body = @app.call(env)
33+
return [status, headers, body] if env['PATH_INFO'].start_with?('/sidekiq')
34+
3335
HEADERS.each { |key, value| headers[key] ||= value }
3436
[status, headers, body]
3537
end

0 commit comments

Comments
 (0)