Files
open-webui/backend/open_webui
Timothy Jaeryang Baek 3bba1c2270 feat: add IFRAME_CSP env var for srcdoc iframe content security policy
Adds an IFRAME_CSP environment variable that injects a Content-Security-Policy
<meta> tag into all srcdoc iframes rendering untrusted content:
- Artifacts (LLM-generated HTML previews)
- FullHeightIframe (tool/embed output)
- FilePreview (user-uploaded HTML files)
- CitationModal (RAG document HTML)

Shared utility in src/lib/utils/csp.ts handles injection with HTML-safe
attribute escaping. URL-based iframes (src=) are correctly excluded.

Env-var only — no PersistentConfig, no admin UI, no DB. Set once at deploy
time, requires restart. Empty string (default) means no CSP restriction.
2026-05-11 01:56:02 +09:00
..
…
2026-05-09 15:25:27 +09:00
2026-05-09 15:25:27 +09:00
2026-05-11 01:46:33 +09:00
2026-05-11 01:15:34 +09:00
2026-05-09 15:21:31 +09:00
2026-04-19 22:45:54 +09:00
2026-04-12 19:08:30 -05:00
2026-03-17 17:58:01 -05:00
2026-05-09 15:25:27 +09:00
2026-05-09 02:38:08 +09:00
2026-04-14 17:27:31 -05:00
2026-05-09 21:05:49 +09:00
2026-05-09 04:17:58 +09:00
2026-03-17 17:58:01 -05:00