]> BookStack Code Mirror - bookstack/commitdiff
SSR: Added new option to complete env example file
authorDan Brown <redacted>
Wed, 30 Aug 2023 01:31:36 +0000 (02:31 +0100)
committerDan Brown <redacted>
Wed, 30 Aug 2023 01:31:36 +0000 (02:31 +0100)
.env.example.complete

index 96a3b448ff4de913254ae3883a8557ffab83d2d9..547e81818823db4a48ba30311e9692c0548b937a 100644 (file)
@@ -359,6 +359,15 @@ ALLOWED_IFRAME_HOSTS=null
 # Current host and source for the "DRAWIO" setting will be auto-appended to the sources configured.
 ALLOWED_IFRAME_SOURCES="https://*.draw.io https://*.youtube.com https://*.youtube-nocookie.com https://*.vimeo.com"
 
+# A list of the sources/hostnames that can be reached by application SSR calls.
+# This is used wherever users can provide URLs/hosts in-platform, like for webhooks.
+# Host-specific functionality (usually controlled via other options) like auth
+# or user avatars for example, won't use this list.
+# Space seperated if multiple. Can use '*' as a wildcard.
+# Values will be compared prefix-matched, case-insensitive, against called SSR urls.
+# Defaults to allow all hosts.
+ALLOWED_SSR_HOSTS="*"
+
 # The default and maximum item-counts for listing API requests.
 API_DEFAULT_ITEM_COUNT=100
 API_MAX_ITEM_COUNT=500