- Content Policy: Allow inline scripts, otherwise there is errors in browser/inspect/console.

- Set default matomo settings to disabled.

Thanks to xet7 !
This commit is contained in:
Lauri Ojansivu 2018-08-15 23:41:01 +03:00
parent 5c33a85341
commit 807c6ce09e
5 changed files with 18 additions and 12 deletions

View file

@ -33,8 +33,8 @@ ENV BUILD_DEPS="apt-utils gnupg gosu wget curl bzip2 build-essential python git
WITH_API=true \
MATOMO_ADDRESS="" \
MATOMO_SITE_ID="" \
MATOMO_DO_NOT_TRACK=false \
MATOMO_WITH_USERNAME=true \
MATOMO_DO_NOT_TRACK=true \
MATOMO_WITH_USERNAME=false \
BROWSER_POLICY_ENABLED=true \
TRUSTED_URL=""

View file

@ -33,6 +33,7 @@ services:
- METEOR_EDGE=${METEOR_EDGE}
- USE_EDGE=${USE_EDGE}
ports:
# Docker outsideport:insideport
- 80:8080
environment:
- MONGO_URL=mongodb://wekandb:27017/wekan
@ -41,14 +42,18 @@ services:
# If you disable Wekan API with 'false', Export Board does not work.
- WITH_API=true
# Optional: Integration with Matomo https://matomo.org that is installed to your server
# The address of the server where Matomo is hosted:
# - MATOMO_ADDRESS=https://example.com/matomo
# The address of the server where Matomo is hosted.
# example: - MATOMO_ADDRESS=https://example.com/matomo
- MATOMO_ADDRESS=''
# The value of the site ID given in Matomo server for Wekan
# - MATOMO_SITE_ID=123456789
# The option do not track which enables users to not be tracked by matomo"
# - MATOMO_DO_NOT_TRACK=false
# example: - MATOMO_SITE_ID=12345
- MATOMO_SITE_ID=''
# The option do not track which enables users to not be tracked by matomo
# example: - MATOMO_DO_NOT_TRACK=false
- MATOMO_DO_NOT_TRACK=true
# The option that allows matomo to retrieve the username:
# - MATOMO_WITH_USERNAME=true
# example: MATOMO_WITH_USERNAME=true
- MATOMO_WITH_USERNAME=false
# Enable browser policy and allow one trusted URL that can have iframe that has Wekan embedded inside.
# Setting this to false is not recommended, it also disables all other browser policy protections
# and allows all iframing etc. See wekan/server/policy.js

View file

@ -240,8 +240,8 @@ const myCommand :Spk.Manifest.Command = (
(key = "WITH_API", value = "true"),
(key = "MATOMO_ADDRESS", value=""),
(key = "MATOMO_SITE_ID", value=""),
(key = "MATOMO_DO_NOT_TRACK", value="false"),
(key = "MATOMO_WITH_USERNAME", value="true"),
(key = "MATOMO_DO_NOT_TRACK", value="true"),
(key = "MATOMO_WITH_USERNAME", value="false"),
(key = "BROWSER_POLICY_ENABLED", value="true"),
(key = "TRUSTED_URL", value=""),
(key = "SANDSTORM", value = "1"),

View file

@ -6,7 +6,8 @@ Meteor.startup(() => {
// Trusted URL that can embed Wekan in iFrame.
const trusted = process.env.TRUSTED_URL;
BrowserPolicy.framing.disallow();
BrowserPolicy.content.disallowInlineScripts();
//Allow inline scripts, otherwise there is errors in browser/inspect/console
//BrowserPolicy.content.disallowInlineScripts();
BrowserPolicy.content.disallowEval();
BrowserPolicy.content.allowInlineStyles();
BrowserPolicy.content.allowFontDataUrl();

View file

@ -61,7 +61,7 @@ DEFAULT_MATOMO_SITE_ID=""
KEY_MATOMO_SITE_ID="matomo-site-id"
DESCRIPTION_MATOMO_DO_NOT_TRACK="The option do not track which enables users to not be tracked by matomo"
DEFAULT_MATOMO_DO_NOT_TRACK="false"
DEFAULT_MATOMO_DO_NOT_TRACK="true"
KEY_MATOMO_DO_NOT_TRACK="matomo-do-not-track"
DESCRIPTION_MATOMO_WITH_USERNAME="The option that allows matomo to retrieve the username"