Completed
Push — master ( d713a5...b9b397 )
by Christoph
19s queued 13s
created

CustomCspListener::handle()   B

Complexity

Conditions 7
Paths 8

Size

Total Lines 25
Code Lines 15

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
cc 7
eloc 15
c 1
b 0
f 0
nc 8
nop 1
dl 0
loc 25
rs 8.8333
1
<?php
2
3
declare(strict_types=1);
4
5
/*
6
 * @copyright 2021 Christoph Wurst <[email protected]>
7
 *
8
 * @author 2021 Christoph Wurst <[email protected]>
9
 *
10
 * @license GNU AGPL version 3 or any later version
11
 *
12
 * This program is free software: you can redistribute it and/or modify
13
 * it under the terms of the GNU Affero General Public License as
14
 * published by the Free Software Foundation, either version 3 of the
15
 * License, or (at your option) any later version.
16
 *
17
 * This program is distributed in the hope that it will be useful,
18
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
19
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
20
 * GNU Affero General Public License for more details.
21
 *
22
 * You should have received a copy of the GNU Affero General Public License
23
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
24
 */
25
26
namespace OCA\Sentry\Listener;
27
28
use OCA\Sentry\Config;
29
use OCP\AppFramework\Http\ContentSecurityPolicy;
30
use OCP\EventDispatcher\Event;
31
use OCP\EventDispatcher\IEventListener;
32
use OCP\Security\CSP\AddContentSecurityPolicyEvent;
33
use function parse_url;
34
35
class CustomCspListener implements IEventListener {
36
37
	/** @var Config */
38
	private $config;
39
40
	public function __construct(Config $config) {
41
		$this->config = $config;
42
	}
43
44
	public function handle(Event $event): void {
45
		if (!($event instanceof AddContentSecurityPolicyEvent)) {
46
			return;
47
		}
48
49
		$publicDsn = $this->config->getPublicDsn();
50
		$reportUrl = $this->config->getCspReportUrl();
51
		if ($publicDsn === null && $reportUrl === null) {
52
			// Don't add any custom CSP
53
			return;
54
		}
55
56
		$csp = new ContentSecurityPolicy();
57
		if ($publicDsn !== null) {
58
			$parsedUrl = parse_url($publicDsn);
59
			if (isset($parsedUrl['scheme'], $parsedUrl['host'])) {
60
				$domain = $parsedUrl['scheme'] . '://' . $parsedUrl['host'];
61
				$csp->addAllowedConnectDomain($domain);
62
			}
63
		}
64
		if ($reportUrl !== null) {
65
			$csp->addReportTo($reportUrl);
66
		}
67
68
		$event->addPolicy($csp);
69
	}
70
71
}
72