mirror of
https://github.com/kevinveenbirkenbach/computer-playbook.git
synced 2025-10-21 05:26:09 +00:00
- sys-front-inj-logout: depend on web-svc-logout (run-once guarded) and simplify task flow. - web-svc-logout: align feature flags/formatting and extend CSP: - add cdn.jsdelivr.net to connect/script/style and quote values. - Nginx: move CORS config into logout-proxy.conf.j2 with dynamic vars: - Access-Control-Allow-Origin set to canonical logout origin, - Allow-Credentials=true, - Allow-Methods=GET, OPTIONS, - basic headers list (Accept, Authorization), - cache disabled for /logout responses. - Drop obsolete CORS var passing from 01_core.yml; headers now templated at proxy layer. Prepares clean cross-origin logout orchestration from https://logout.veen.world. Refs: ChatGPT discussion – https://chatgpt.com/share/68ebb75f-0170-800f-93c5-e5cb438b8ed4
31 lines
770 B
YAML
31 lines
770 B
YAML
- name: "Add logout domains to CSP connect-src"
|
|
set_fact:
|
|
applications: >-
|
|
{{
|
|
applications | combine(
|
|
{
|
|
application_id: {
|
|
'server': {
|
|
'csp': {
|
|
'whitelist': {
|
|
'connect-src': LOGOUT_CONNECT_SRC_NEW
|
|
}
|
|
}
|
|
}
|
|
}
|
|
},
|
|
recursive=True
|
|
)
|
|
}}
|
|
|
|
- name: "load docker, proxy for '{{ application_id }}'"
|
|
include_role:
|
|
name: sys-stk-full-stateless
|
|
|
|
- name: Create symbolic link from .env file to repository
|
|
file:
|
|
src: "{{ docker_compose.files.env }}"
|
|
dest: "{{ [ docker_repository_path, '.env' ] | path_join }}"
|
|
state: link
|
|
|
|
- include_tasks: utils/run_once.yml |