Files
open-webui/src/lib/utils
Timothy Jaeryang Baek 3bba1c2270 feat: add IFRAME_CSP env var for srcdoc iframe content security policy
Adds an IFRAME_CSP environment variable that injects a Content-Security-Policy
<meta> tag into all srcdoc iframes rendering untrusted content:
- Artifacts (LLM-generated HTML previews)
- FullHeightIframe (tool/embed output)
- FilePreview (user-uploaded HTML files)
- CitationModal (RAG document HTML)

Shared utility in src/lib/utils/csp.ts handles injection with HTML-safe
attribute escaping. URL-based iframes (src=) are correctly excluded.

Env-var only — no PersistentConfig, no admin UI, no DB. Set once at deploy
time, requires restart. Empty string (default) means no CSP restriction.
2026-05-11 01:56:02 +09:00
..
2026-04-13 21:52:19 -05:00
2026-05-09 04:22:46 +09:00
2026-03-06 20:12:37 -06:00
2026-03-23 23:39:52 -05:00
2026-03-06 20:12:37 -06:00
2024-12-16 15:11:05 -05:00
2026-05-09 15:25:27 +09:00
2026-04-12 19:13:13 -05:00
2026-03-06 20:12:37 -06:00
2025-11-19 03:51:10 -05:00