diff --git a/Makefile b/Makefile index 4b630d6b..d40d67b1 100644 --- a/Makefile +++ b/Makefile @@ -34,9 +34,11 @@ API_ROOT_PATH=/ API_TRACE_HEADER=Gotenberg-Trace API_DISABLE_HEALTH_CHECK_LOGGING=false CHROMIUM_INCOGNITO=false +CHROMIUM_ALLOW_INSECURE_LOCALHOST=false CHROMIUM_IGNORE_CERTIFICATE_ERRORS=false CHROMIUM_DISABLE_WEB_SECURITY=false CHROMIUM_ALLOW_FILE_ACCESS_FROM_FILES=false +CHROMIUM_HOST_RESOLVER_RULES= CHROMIUM_PROXY_SERVER= CHROMIUM_ALLOW_LIST= CHROMIUM_DENY_LIST="^file:///[^tmp].*" @@ -77,9 +79,11 @@ run: ## Start a Gotenberg container --api-trace-header=$(API_TRACE_HEADER) \ --api-disable-health-check-logging=$(API_DISABLE_HEALTH_CHECK_LOGGING) \ --chromium-incognito=$(CHROMIUM_INCOGNITO) \ + --chromium-allow-insecure-localhost=$(CHROMIUM_ALLOW_INSECURE_LOCALHOST) \ --chromium-ignore-certificate-errors=$(CHROMIUM_IGNORE_CERTIFICATE_ERRORS) \ --chromium-disable-web-security=$(CHROMIUM_DISABLE_WEB_SECURITY) \ --chromium-allow-file-access-from-files=$(CHROMIUM_ALLOW_FILE_ACCESS_FROM_FILES) \ + --chromium-host-resolver-rules=$(CHROMIUM_HOST_RESOLVER_RULES) \ --chromium-proxy-server=$(CHROMIUM_PROXY_SERVER) \ --chromium-allow-list=$(CHROMIUM_ALLOW_LIST) \ --chromium-deny-list=$(CHROMIUM_DENY_LIST) \ diff --git a/pkg/modules/chromium/chromium.go b/pkg/modules/chromium/chromium.go index 52bd82cf..fde7193b 100644 --- a/pkg/modules/chromium/chromium.go +++ b/pkg/modules/chromium/chromium.go @@ -66,9 +66,11 @@ type Chromium struct { engine gotenberg.PDFEngine userAgent string incognito bool + allowInsecureLocalhost bool ignoreCertificateErrors bool disableWebSecurity bool allowFileAccessFromFiles bool + hostResolverRules string proxyServer string allowList *regexp.Regexp denyList *regexp.Regexp @@ -250,9 +252,11 @@ func (mod Chromium) Descriptor() gotenberg.ModuleDescriptor { fs := flag.NewFlagSet("chromium", flag.ExitOnError) fs.String("chromium-user-agent", "", "Override the default User-Agent header") fs.Bool("chromium-incognito", false, "Start Chromium with incognito mode") + fs.Bool("chromium-allow-insecure-localhost", false, "Ignore TLS/SSL errors on localhost") fs.Bool("chromium-ignore-certificate-errors", false, "Ignore the certificate errors") fs.Bool("chromium-disable-web-security", false, "Don't enforce the same-origin policy") fs.Bool("chromium-allow-file-access-from-files", false, "Allow file:// URIs to read other file:// URIs") + fs.String("chromium-host-resolver-rules", "", "Set custom mappings to the host resolver") fs.String("chromium-proxy-server", "", "Set the outbound proxy server; this switch only affects HTTP and HTTPS requests") fs.String("chromium-allow-list", "", "Set the allowed URLs for Chromium using a regular expression") fs.String("chromium-deny-list", "^file:///[^tmp].*", "Set the denied URLs for Chromium using a regular expression") @@ -274,9 +278,11 @@ func (mod Chromium) Descriptor() gotenberg.ModuleDescriptor { func (mod *Chromium) Provision(ctx *gotenberg.Context) error { flags := ctx.ParsedFlags() mod.userAgent = flags.MustString("chromium-user-agent") + mod.allowInsecureLocalhost = flags.MustBool("chromium-allow-insecure-localhost") mod.ignoreCertificateErrors = flags.MustBool("chromium-ignore-certificate-errors") mod.disableWebSecurity = flags.MustBool("chromium-disable-web-security") mod.allowFileAccessFromFiles = flags.MustBool("chromium-allow-file-access-from-files") + mod.hostResolverRules = flags.MustString("chromium-host-resolver-rules") mod.proxyServer = flags.MustString("chromium-proxy-server") mod.allowList = flags.MustRegexp("chromium-allow-list") mod.denyList = flags.MustRegexp("chromium-deny-list") @@ -382,6 +388,11 @@ func (mod Chromium) PDF(ctx context.Context, logger *zap.Logger, URL, outputPath args = append(args, chromedp.Flag("incognito", mod.incognito)) } + if mod.allowInsecureLocalhost { + // See https://github.com/gotenberg/gotenberg/issues/488. + args = append(args, chromedp.Flag("allow-insecure-localhost", true)) + } + if mod.ignoreCertificateErrors { args = append(args, chromedp.IgnoreCertErrors) } @@ -395,6 +406,11 @@ func (mod Chromium) PDF(ctx context.Context, logger *zap.Logger, URL, outputPath args = append(args, chromedp.Flag("allow-file-access-from-files", true)) } + if mod.hostResolverRules != "" { + // See https://github.com/gotenberg/gotenberg/issues/488. + args = append(args, chromedp.Flag("host-resolver-rules", mod.hostResolverRules)) + } + if mod.proxyServer != "" { // See https://github.com/gotenberg/gotenberg/issues/376. args = append(args, chromedp.ProxyServer(mod.proxyServer)) diff --git a/pkg/modules/chromium/chromium_test.go b/pkg/modules/chromium/chromium_test.go index e5bfd9a6..1f11050b 100644 --- a/pkg/modules/chromium/chromium_test.go +++ b/pkg/modules/chromium/chromium_test.go @@ -231,9 +231,11 @@ func TestChromium_PDF(t *testing.T) { options Options userAgent string incognito bool + allowInsecureLocalhost bool ignoreCertificateErrors bool disableWebSecurity bool allowFileAccessFromFiles bool + hostResolverRules string proxyServer string allowList *regexp.Regexp denyList *regexp.Regexp @@ -379,8 +381,10 @@ func TestChromium_PDF(t *testing.T) { userAgent: "foo", incognito: true, ignoreCertificateErrors: true, + allowInsecureLocalhost: true, disableWebSecurity: true, allowFileAccessFromFiles: true, + hostResolverRules: "foo", proxyServer: "foo", }, { @@ -431,9 +435,11 @@ func TestChromium_PDF(t *testing.T) { mod.binPath = os.Getenv("CHROMIUM_BIN_PATH") mod.userAgent = tc.userAgent mod.incognito = tc.incognito + mod.allowInsecureLocalhost = tc.allowInsecureLocalhost mod.ignoreCertificateErrors = tc.ignoreCertificateErrors mod.disableWebSecurity = tc.disableWebSecurity mod.allowFileAccessFromFiles = tc.allowFileAccessFromFiles + mod.hostResolverRules = tc.hostResolverRules mod.proxyServer = tc.proxyServer if tc.allowList == nil {