Skip to content
Snippets Groups Projects
Unverified Commit 3d1b3059 authored by Aleksander Nicacio da Silva's avatar Aleksander Nicacio da Silva Committed by Diego Sampaio
Browse files

fix: Livechat `CSP` whitelist validation (#29278)

parent 2b042436
No related branches found
No related tags found
No related merge requests found
---
"@rocket.chat/meteor": patch
---
fixes the Livechat CSP validation, which was incorrectly blocking access to the widget for all non whitelisted domains
......@@ -21,7 +21,7 @@ WebApp.connectHandlers.use('/livechat', (req, res, next) => {
const domainWhiteListSetting = settings.get<string>('Livechat_AllowedDomainsList');
let domainWhiteList = [];
if (req.headers.referer && !domainWhiteListSetting.trim()) {
if (req.headers.referer && domainWhiteListSetting.trim()) {
domainWhiteList = domainWhiteListSetting.split(',').map((domain) => domain.trim());
const referer = url.parse(req.headers.referer);
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment