web-svc-logout: merge logout domains into CSP connect-src and refactor task flow

• Add tasks/01_core.yml to set applications[application_id].server.csp.whitelist['connect-src'] = LOGOUT_CONNECT_SRC_NEW.

• Switch tasks/main.yml to include 01_core.yml (run-once guard preserved).

• Update templates/env.j2 to emit LOGOUT_DOMAINS as a comma-separated list.

• Rework vars/main.yml: compute LOGOUT_DOMAINS, derive LOGOUT_ORIGINS with WEB_PROTOCOL, read connect-src via the get_app_conf filter, and merge/dedupe (unique).

Rationale: ensure CSP allows cross-domain logout requests for all configured services.

Conversation: https://chatgpt.com/share/68b5b07d-b208-800f-b6b2-f26934607c8a
This commit is contained in:
2025-09-01 16:41:33 +02:00
parent b834f0c95c
commit 4ae3cee36c
4 changed files with 37 additions and 16 deletions

View File

@@ -1,5 +1,5 @@
# Commaseparated list of all subdomains to log out (no spaces)
LOGOUT_DOMAINS={{ logout_domains }}
LOGOUT_DOMAINS={{ LOGOUT_DOMAINS | join(',') }}
# Port the logout service will listen on inside the container
LOGOUT_PORT={{ container_port }}