From 698b7fb056093e3a9cc24db9299101c18a1fa0b3 Mon Sep 17 00:00:00 2001 From: GraphicHealer Date: Mon, 5 Aug 2024 17:18:15 -0400 Subject: [PATCH] Update apprelays.js to fix Header issue (#6306) Add `.trim()` to the header label value (`i`) to fix a rare circumstance where there can be a space in the header name. --- apprelays.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apprelays.js b/apprelays.js index 388a0fcd08..5a9172acbf 100644 --- a/apprelays.js +++ b/apprelays.js @@ -717,7 +717,7 @@ module.exports.CreateWebRelay = function (parent, db, args, domain, mtype) { } } } - else if (blockHeaders.indexOf(i) == -1) { obj.res.set(i, header[i]); } // Set the headers if not blocked + else if (blockHeaders.indexOf(i) == -1) { obj.res.set(i.trim(), header[i]); } // Set the headers if not blocked } obj.res.set('Content-Security-Policy', "default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob:;"); // Set an "allow all" policy, see if the can restrict this in the future //obj.res.set('Content-Security-Policy', "default-src * 'unsafe-inline' 'unsafe-eval'; script-src * 'unsafe-inline' 'unsafe-eval'; connect-src * 'unsafe-inline'; img-src * data: blob: 'unsafe-inline'; frame-src *; style-src * 'unsafe-inline';"); // Set an "allow all" policy, see if the can restrict this in the future