Allow inline javascript and CSS in better_errors pages
authorTom Hughes <tom@compton.nu>
Sun, 17 Jun 2018 10:33:04 +0000 (11:33 +0100)
committerTom Hughes <tom@compton.nu>
Sun, 17 Jun 2018 10:33:51 +0000 (11:33 +0100)
.rubocop.yml
app/controllers/application_controller.rb

index fc2b5cd85c884c5c40117df99ec75ae7b884d36b..e12437e080c3d8f0d81731537acf0847ecfbf8bf 100644 (file)
@@ -9,6 +9,7 @@ Layout/ExtraSpacing:
 Lint/PercentStringArray:
   Exclude:
     - 'config/initializers/secure_headers.rb'
+    - 'app/controllers/application_controller.rb'
     - 'app/controllers/site_controller.rb'
 
 Naming/FileName:
index 3afb17f470afb5668a2c2be34e60696f4c57f952..db4ae9ad392f20f91a60d6c251f8244633cc7d34 100644 (file)
@@ -4,6 +4,7 @@ class ApplicationController < ActionController::Base
   protect_from_forgery :with => :exception
 
   before_action :fetch_body
+  around_action :better_errors_allow_inline, :if => proc { Rails.env.development? }
 
   attr_accessor :current_user
   helper_method :current_user
@@ -455,6 +456,17 @@ class ApplicationController < ActionController::Base
     end
   end
 
+  def better_errors_allow_inline
+    yield
+  rescue StandardError
+    append_content_security_policy_directives(
+      :script_src => %w['unsafe-inline'],
+      :style_src => %w['unsafe-inline']
+    )
+
+    raise
+  end
+
   private
 
   # extract authorisation credentials from headers, returns user = nil if none