mirror of
				https://github.com/kevinveenbirkenbach/computer-playbook.git
				synced 2025-10-25 23:41:10 +00:00 
			
		
		
		
	- Add reusable Nginx include: roles/sys-svc-proxy/templates/headers/access_control_allow.conf.j2
  (dynamic ACAO/credentials/methods/headers via role vars)
- Set global 'Vary: Origin' in nginx.conf.j2 to prevent cache poisoning
- CSP: allow Simple Icons via connect-src when feature is enabled
- Front proxy: rename vars to lowercase + flush handlers after config deploy
- Desktop: gate & load Simple Icons role; inject brand logos when enabled
- Bluesky + Logout: replace inline CORS with centralized include
- Simpleicons: public CORS (ACAO='*', no credentials), keep GET/OPTIONS, allow headers
- Taiga: adjust canonical domain to taiga.kanban.{{ PRIMARY_DOMAIN }}
- LibreTranslate: remove unused images/versions keys
Fixes: https://open.project.infinito.nexus/projects/cymais/work_packages/342/activity
Discussion: https://chatgpt.com/share/68da5e27-ffd4-800f-91a3-0ef103058d44
		
	
		
			
				
	
	
		
			61 lines
		
	
	
		
			2.1 KiB
		
	
	
	
		
			Django/Jinja
		
	
	
	
	
	
			
		
		
	
	
			61 lines
		
	
	
		
			2.1 KiB
		
	
	
	
		
			Django/Jinja
		
	
	
	
	
	
| server
 | |
| {
 | |
|   server_name {{ domain }};
 | |
|   {% include 'roles/sys-svc-proxy/templates/headers/buffers.conf.j2' %}
 | |
|   
 | |
|   {% if applications | get_app_conf(application_id, 'features.oauth2', False) %}
 | |
|     {% include 'roles/web-app-oauth2-proxy/templates/endpoint.conf.j2'%}
 | |
|   {% endif %}
 | |
| 
 | |
|   {% include 'roles/sys-front-inj-all/templates/server.conf.j2'%}
 | |
|   
 | |
|   {% if proxy_extra_configuration is defined %}
 | |
|     {# Additional Domain Specific Configuration #}
 | |
|     {{ proxy_extra_configuration }}
 | |
|   {% endif %}
 | |
| 
 | |
|   {% include 'roles/sys-svc-letsencrypt/templates/ssl_header.j2' %}
 | |
| 
 | |
|   {% if applications | get_app_conf(application_id, 'features.oauth2', False) %}
 | |
|     {% set acl = applications | get_app_conf(application_id, 'oauth2_proxy.acl', False, {}) %}
 | |
| 
 | |
|     {% if acl.blacklist is defined %}
 | |
|       {# 1. Expose everything by default, then protect blacklisted paths #}
 | |
|       {% set oauth2_proxy_enabled = false %}
 | |
|       {% set location = "/" %}
 | |
|       {% include 'roles/sys-svc-proxy/templates/location/html.conf.j2' %}
 | |
| 
 | |
|       {% for loc in acl.blacklist %}
 | |
|         {% set oauth2_proxy_enabled = true %}
 | |
|         {% set location = loc %}
 | |
|         {% include 'roles/sys-svc-proxy/templates/location/html.conf.j2' %}
 | |
|       {% endfor %}
 | |
| 
 | |
|     {% elif acl.whitelist is defined %}
 | |
|       {# 2. Protect everything by default, then expose whitelisted paths #}
 | |
|       {% set oauth2_proxy_enabled = true %}
 | |
|       {% set location = "/" %}
 | |
|       {% include 'roles/sys-svc-proxy/templates/location/html.conf.j2' %}
 | |
| 
 | |
|       {% for loc in acl.whitelist %}
 | |
|         {% set oauth2_proxy_enabled = false %}
 | |
|         {% set location = loc %}
 | |
|         {% include 'roles/sys-svc-proxy/templates/location/html.conf.j2' %}
 | |
|       {% endfor %}
 | |
| 
 | |
|     {% else %}
 | |
|       {# 3. OAuth2 enabled but no (or empty) ACL — protect all #}
 | |
|       {% set oauth2_proxy_enabled = true %}
 | |
|       {% set location = "/" %}
 | |
|       {% include 'roles/sys-svc-proxy/templates/location/html.conf.j2' %}
 | |
|     {% endif %}
 | |
| 
 | |
|   {% else %}
 | |
|     {# 4. OAuth2 completely disabled — expose all #}
 | |
|     {% set oauth2_proxy_enabled = false %}
 | |
|     {% set location = "/" %}
 | |
|     {% include 'roles/sys-svc-proxy/templates/location/html.conf.j2' %}
 | |
|   {% endif %}
 | |
| 
 | |
| }
 |