mirror of
https://github.com/gotenberg/gotenberg.git
synced 2026-08-08 00:22:14 +01:00
feat(chromium): new flags chromium-allow-insecure-localhost and chromium-host-resolver-rules
This commit is contained in:
4
Makefile
4
Makefile
@@ -34,9 +34,11 @@ API_ROOT_PATH=/
|
||||
API_TRACE_HEADER=Gotenberg-Trace
|
||||
API_DISABLE_HEALTH_CHECK_LOGGING=false
|
||||
CHROMIUM_INCOGNITO=false
|
||||
CHROMIUM_ALLOW_INSECURE_LOCALHOST=false
|
||||
CHROMIUM_IGNORE_CERTIFICATE_ERRORS=false
|
||||
CHROMIUM_DISABLE_WEB_SECURITY=false
|
||||
CHROMIUM_ALLOW_FILE_ACCESS_FROM_FILES=false
|
||||
CHROMIUM_HOST_RESOLVER_RULES=
|
||||
CHROMIUM_PROXY_SERVER=
|
||||
CHROMIUM_ALLOW_LIST=
|
||||
CHROMIUM_DENY_LIST="^file:///[^tmp].*"
|
||||
@@ -77,9 +79,11 @@ run: ## Start a Gotenberg container
|
||||
--api-trace-header=$(API_TRACE_HEADER) \
|
||||
--api-disable-health-check-logging=$(API_DISABLE_HEALTH_CHECK_LOGGING) \
|
||||
--chromium-incognito=$(CHROMIUM_INCOGNITO) \
|
||||
--chromium-allow-insecure-localhost=$(CHROMIUM_ALLOW_INSECURE_LOCALHOST) \
|
||||
--chromium-ignore-certificate-errors=$(CHROMIUM_IGNORE_CERTIFICATE_ERRORS) \
|
||||
--chromium-disable-web-security=$(CHROMIUM_DISABLE_WEB_SECURITY) \
|
||||
--chromium-allow-file-access-from-files=$(CHROMIUM_ALLOW_FILE_ACCESS_FROM_FILES) \
|
||||
--chromium-host-resolver-rules=$(CHROMIUM_HOST_RESOLVER_RULES) \
|
||||
--chromium-proxy-server=$(CHROMIUM_PROXY_SERVER) \
|
||||
--chromium-allow-list=$(CHROMIUM_ALLOW_LIST) \
|
||||
--chromium-deny-list=$(CHROMIUM_DENY_LIST) \
|
||||
|
||||
@@ -66,9 +66,11 @@ type Chromium struct {
|
||||
engine gotenberg.PDFEngine
|
||||
userAgent string
|
||||
incognito bool
|
||||
allowInsecureLocalhost bool
|
||||
ignoreCertificateErrors bool
|
||||
disableWebSecurity bool
|
||||
allowFileAccessFromFiles bool
|
||||
hostResolverRules string
|
||||
proxyServer string
|
||||
allowList *regexp.Regexp
|
||||
denyList *regexp.Regexp
|
||||
@@ -250,9 +252,11 @@ func (mod Chromium) Descriptor() gotenberg.ModuleDescriptor {
|
||||
fs := flag.NewFlagSet("chromium", flag.ExitOnError)
|
||||
fs.String("chromium-user-agent", "", "Override the default User-Agent header")
|
||||
fs.Bool("chromium-incognito", false, "Start Chromium with incognito mode")
|
||||
fs.Bool("chromium-allow-insecure-localhost", false, "Ignore TLS/SSL errors on localhost")
|
||||
fs.Bool("chromium-ignore-certificate-errors", false, "Ignore the certificate errors")
|
||||
fs.Bool("chromium-disable-web-security", false, "Don't enforce the same-origin policy")
|
||||
fs.Bool("chromium-allow-file-access-from-files", false, "Allow file:// URIs to read other file:// URIs")
|
||||
fs.String("chromium-host-resolver-rules", "", "Set custom mappings to the host resolver")
|
||||
fs.String("chromium-proxy-server", "", "Set the outbound proxy server; this switch only affects HTTP and HTTPS requests")
|
||||
fs.String("chromium-allow-list", "", "Set the allowed URLs for Chromium using a regular expression")
|
||||
fs.String("chromium-deny-list", "^file:///[^tmp].*", "Set the denied URLs for Chromium using a regular expression")
|
||||
@@ -274,9 +278,11 @@ func (mod Chromium) Descriptor() gotenberg.ModuleDescriptor {
|
||||
func (mod *Chromium) Provision(ctx *gotenberg.Context) error {
|
||||
flags := ctx.ParsedFlags()
|
||||
mod.userAgent = flags.MustString("chromium-user-agent")
|
||||
mod.allowInsecureLocalhost = flags.MustBool("chromium-allow-insecure-localhost")
|
||||
mod.ignoreCertificateErrors = flags.MustBool("chromium-ignore-certificate-errors")
|
||||
mod.disableWebSecurity = flags.MustBool("chromium-disable-web-security")
|
||||
mod.allowFileAccessFromFiles = flags.MustBool("chromium-allow-file-access-from-files")
|
||||
mod.hostResolverRules = flags.MustString("chromium-host-resolver-rules")
|
||||
mod.proxyServer = flags.MustString("chromium-proxy-server")
|
||||
mod.allowList = flags.MustRegexp("chromium-allow-list")
|
||||
mod.denyList = flags.MustRegexp("chromium-deny-list")
|
||||
@@ -382,6 +388,11 @@ func (mod Chromium) PDF(ctx context.Context, logger *zap.Logger, URL, outputPath
|
||||
args = append(args, chromedp.Flag("incognito", mod.incognito))
|
||||
}
|
||||
|
||||
if mod.allowInsecureLocalhost {
|
||||
// See https://github.com/gotenberg/gotenberg/issues/488.
|
||||
args = append(args, chromedp.Flag("allow-insecure-localhost", true))
|
||||
}
|
||||
|
||||
if mod.ignoreCertificateErrors {
|
||||
args = append(args, chromedp.IgnoreCertErrors)
|
||||
}
|
||||
@@ -395,6 +406,11 @@ func (mod Chromium) PDF(ctx context.Context, logger *zap.Logger, URL, outputPath
|
||||
args = append(args, chromedp.Flag("allow-file-access-from-files", true))
|
||||
}
|
||||
|
||||
if mod.hostResolverRules != "" {
|
||||
// See https://github.com/gotenberg/gotenberg/issues/488.
|
||||
args = append(args, chromedp.Flag("host-resolver-rules", mod.hostResolverRules))
|
||||
}
|
||||
|
||||
if mod.proxyServer != "" {
|
||||
// See https://github.com/gotenberg/gotenberg/issues/376.
|
||||
args = append(args, chromedp.ProxyServer(mod.proxyServer))
|
||||
|
||||
@@ -231,9 +231,11 @@ func TestChromium_PDF(t *testing.T) {
|
||||
options Options
|
||||
userAgent string
|
||||
incognito bool
|
||||
allowInsecureLocalhost bool
|
||||
ignoreCertificateErrors bool
|
||||
disableWebSecurity bool
|
||||
allowFileAccessFromFiles bool
|
||||
hostResolverRules string
|
||||
proxyServer string
|
||||
allowList *regexp.Regexp
|
||||
denyList *regexp.Regexp
|
||||
@@ -379,8 +381,10 @@ func TestChromium_PDF(t *testing.T) {
|
||||
userAgent: "foo",
|
||||
incognito: true,
|
||||
ignoreCertificateErrors: true,
|
||||
allowInsecureLocalhost: true,
|
||||
disableWebSecurity: true,
|
||||
allowFileAccessFromFiles: true,
|
||||
hostResolverRules: "foo",
|
||||
proxyServer: "foo",
|
||||
},
|
||||
{
|
||||
@@ -431,9 +435,11 @@ func TestChromium_PDF(t *testing.T) {
|
||||
mod.binPath = os.Getenv("CHROMIUM_BIN_PATH")
|
||||
mod.userAgent = tc.userAgent
|
||||
mod.incognito = tc.incognito
|
||||
mod.allowInsecureLocalhost = tc.allowInsecureLocalhost
|
||||
mod.ignoreCertificateErrors = tc.ignoreCertificateErrors
|
||||
mod.disableWebSecurity = tc.disableWebSecurity
|
||||
mod.allowFileAccessFromFiles = tc.allowFileAccessFromFiles
|
||||
mod.hostResolverRules = tc.hostResolverRules
|
||||
mod.proxyServer = tc.proxyServer
|
||||
|
||||
if tc.allowList == nil {
|
||||
|
||||
Reference in New Issue
Block a user