Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 5 additions & 16 deletions src/middleware.ts
Original file line number Diff line number Diff line change
Expand Up @@ -64,24 +64,13 @@ export const onRequest: MiddlewareHandler = async (context, next) => {
? "script-src 'self' 'unsafe-inline' 'unsafe-eval'"
: "script-src 'self'",

// NETWORK (HMR, APIs, etc.) — bsky.tech.ieeevis.org is the Bluesky
// discussion API for paper pages, public.api.bsky.app the Bluesky AppView
// that threads are read from directly. The Auth0 domain is attendee
// sign-in (lib/auth0Client.ts): a public SPA client talking straight to
// Auth0's token endpoint for login and silent token refresh, no server
// in between. The rest is "log in with Bluesky"
// (components/bluesky/oauth.ts): the browser resolves the handle at
// bsky.social, looks the account up at plc.directory, and then talks to
// the account's own PDS — *.bsky.network for accounts Bluesky hosts. A
// self-hosted PDS is on some other host and will show up in the CSP
// reports; widen this if that turns out common.
// NETWORK (HMR, APIs, etc.) — "log in with Bluesky"
// (components/bluesky/oauth.ts) talks to the reader's own PDS and
// authorization server, which can be on any host: Eurosky, a self-hosted
// PDS, or a did:web account. A list of hosts locks those readers out.
isDev
? "connect-src 'self' ws: http: https:"
: `connect-src 'self' https://bsky.tech.ieeevis.org https://public.api.bsky.app https://bsky.social https://*.bsky.network https://plc.directory${
import.meta.env.PUBLIC_AUTH0_DOMAIN
? ` https://${import.meta.env.PUBLIC_AUTH0_DOMAIN}`
: ""
}`,
: "connect-src 'self' https:",

// Enforce HTTPS in prod only
!isDev && "upgrade-insecure-requests",
Expand Down
Loading