Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. CSP Issues

CSP Issues

Scheduled Pinned Locked Moved Unsolved Support
csp
3 Posts 2 Posters 26 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • apesorgukA Offline
    apesorgukA Offline
    apesorguk
    wrote last edited by
    #1

    So I found an issue with 3 apps when setting the ability to embed.

    Freescout, Chatwoot and Open WebUI

    Using the preset configuration to allow embedding

    # Allow embedding from all sites
    default-src 'self';
    frame-ancestors 'none';
    

    It cause a issue with Freescout and Chatwoot loading at all when going directly and shows an error on the website embedding it.

    I thought the app became currupt so I installed the setup again and tried to add the CSP again to face the same issue. Chatwoot after removing the CSP did not work but freescout worked again.

    Open WebUI just shows a huge Open WebUI logo.

    1 Reply Last reply
    0
    • nebulonN Offline
      nebulonN Offline
      nebulon
      Staff
      wrote last edited by
      #2

      Generally embedding via iframing is not a great idea, since it enables clickjacking attacks. In Cloudron you can however overwrite the csp related headers as you have done. This still does not mean apps itself allow this, they might set (and actually should in my opinion) those csp values in meta tags itself. So even if the apps you want to use do not have their own security measures here, you might still only want to allow specific origins here, otherweise anyone can embedd your apps and perform an attack.

      1 Reply Last reply
      0
      • apesorgukA Offline
        apesorgukA Offline
        apesorguk
        wrote last edited by
        #3

        They were only being embedded for the staff on our Nextcloud, not for the public. And we did restrict to our internal domains and had the same issues.

        Just thought people should know that some apps don't work at all with CSP, causing these apps GUI to stop loading complely making it look like the app no longer works.

        1 Reply Last reply
        0
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Bookmarks
        • Search