From 38f017cdae12e5bbb6b3903a10616f8637de6285 Mon Sep 17 00:00:00 2001 From: Andrew Dryga Date: Fri, 29 Sep 2023 16:54:58 -0600 Subject: [PATCH] Test a different strategy to check for ws origin --- elixir/apps/web/lib/web/endpoint.ex | 1 - elixir/config/runtime.exs | 4 ++++ 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/elixir/apps/web/lib/web/endpoint.ex b/elixir/apps/web/lib/web/endpoint.ex index 09ba1f0e7..34244a444 100644 --- a/elixir/apps/web/lib/web/endpoint.ex +++ b/elixir/apps/web/lib/web/endpoint.ex @@ -39,7 +39,6 @@ defmodule Web.Endpoint do socket "/live", Phoenix.LiveView.Socket, websocket: [ - check_origin: :conn, connect_info: [ :trace_context_headers, :user_agent, diff --git a/elixir/config/runtime.exs b/elixir/config/runtime.exs index 6c6249171..94869970e 100644 --- a/elixir/config/runtime.exs +++ b/elixir/config/runtime.exs @@ -82,6 +82,10 @@ if config_env() == :prod do path: external_url_path ], secret_key_base: compile_config!(:secret_key_base), + check_origin: [ + "#{external_url_scheme}://#{external_url_host}", + "#{external_url_scheme}://*.#{external_url_host}" + ], live_view: [ signing_salt: compile_config!(:live_view_signing_salt) ]