mirror of
https://github.com/InvoiceShelf/InvoiceShelf.git
synced 2026-09-06 15:14:13 +00:00
Backport of InvoiceShelf/InvoiceShelf#691 to 2.x, for the reporter of #688 who is on 2.4.1. The guard added in the 2.4.0 security round rejects private addresses, which includes the shipped default host `http://pdf:3000` and every Docker Compose sidecar deployment. So the guard rejects its own default and Gotenberg cannot be configured at all on the standard setup — a usability regression introduced by a security patch, which is why this lands during the 2.x feature freeze. GOTENBERG_ALLOWED_PRIVATE_HOST names the single host that may skip the check. It is deliberately not a boolean and not settable from the admin UI: the driver streams the upstream response body back as the PDF, so a blanket "allow private" switch would let gotenberg_host be repointed at a link-local metadata endpoint and the response read back. Naming one host keeps the sidecar working while every other private target stays blocked. GotenbergHostPolicy owns the comparison so the save-time rule and the runtime driver guard cannot drift, normalising case, trailing slash and surrounding whitespace on both sides. Note this differs from 3.x in one respect: SafeRemoteUrl rejects hosts that do not resolve, where 3.x's PrivateNetworkGuard lets them through. That behaviour is unchanged here — a typo'd host is still refused at save time on 2.x, which is the friendlier outcome.
35 lines
1018 B
Bash
35 lines
1018 B
Bash
APP_ENV=production
|
|
APP_DEBUG=false
|
|
APP_KEY=base64:kgk/4DW1vEVy7aEvet5FPp5un6PIGe/so8H0mvoUtW0=
|
|
|
|
APP_NAME="InvoiceShelf"
|
|
APP_TIMEZONE=UTC
|
|
APP_URL=
|
|
APP_LOCALE=en
|
|
|
|
DB_CONNECTION=sqlite
|
|
DB_HOST=
|
|
DB_PORT=
|
|
DB_DATABASE=
|
|
DB_USERNAME=
|
|
DB_PASSWORD=
|
|
|
|
SESSION_DOMAIN=null
|
|
SANCTUM_STATEFUL_DOMAIN=
|
|
TRUSTED_PROXIES="*"
|
|
|
|
# Dompdf: keep false so untrusted HTML in PDF notes cannot trigger outbound requests (SSRF).
|
|
# Set true only if you fully trust all PDF HTML and need remote images/CSS.
|
|
DOMPDF_ENABLE_REMOTE=false
|
|
|
|
# Gotenberg (optional alternative PDF driver; the default is dompdf).
|
|
# PDF_DRIVER=gotenberg
|
|
# GOTENBERG_HOST=http://pdf:3000
|
|
# GOTENBERG_PAPERSIZE="210mm 297mm"
|
|
#
|
|
# Gotenberg is normally a sidecar on a private network, which the SSRF guard
|
|
# rejects. Name that one host to exempt it — and only it. Every other private
|
|
# target stays blocked, so the host cannot later be repointed at an internal
|
|
# service. Leave unset unless you actually run Gotenberg privately.
|
|
# GOTENBERG_ALLOWED_PRIVATE_HOST=http://pdf:3000
|