Files
computer-playbook/roles/web-svc-logout/tasks/01_core.yml
Kevin Veen-Birkenbach a996e2190f feat(logout): wire injector to web-svc-logout and add robust CORS/CSP for /logout
- sys-front-inj-logout: depend on web-svc-logout (run-once guarded) and simplify task flow.
- web-svc-logout: align feature flags/formatting and extend CSP:
  - add cdn.jsdelivr.net to connect/script/style and quote values.
- Nginx: move CORS config into logout-proxy.conf.j2 with dynamic vars:
  - Access-Control-Allow-Origin set to canonical logout origin,
  - Allow-Credentials=true,
  - Allow-Methods=GET, OPTIONS,
  - basic headers list (Accept, Authorization),
  - cache disabled for /logout responses.
- Drop obsolete CORS var passing from 01_core.yml; headers now templated at proxy layer.

Prepares clean cross-origin logout orchestration from https://logout.veen.world.

Refs: ChatGPT discussion – https://chatgpt.com/share/68ebb75f-0170-800f-93c5-e5cb438b8ed4
2025-10-12 16:16:47 +02:00

31 lines
770 B
YAML

- name: "Add logout domains to CSP connect-src"
set_fact:
applications: >-
{{
applications | combine(
{
application_id: {
'server': {
'csp': {
'whitelist': {
'connect-src': LOGOUT_CONNECT_SRC_NEW
}
}
}
}
},
recursive=True
)
}}
- name: "load docker, proxy for '{{ application_id }}'"
include_role:
name: sys-stk-full-stateless
- name: Create symbolic link from .env file to repository
file:
src: "{{ docker_compose.files.env }}"
dest: "{{ [ docker_repository_path, '.env' ] | path_join }}"
state: link
- include_tasks: utils/run_once.yml