[Enhancement] Misc fixes 2024-03-29 (#150)
* Removes header to allow embedding in frame * Escaped links in podcast RSS builder * Turned homepage sections into clickable links * Enabled live dashboard in all ENVs * Ensured download worker always returns a 2-member tuple
This commit is contained in:
+11
-14
@@ -1,5 +1,6 @@
|
||||
defmodule PinchflatWeb.Router do
|
||||
use PinchflatWeb, :router
|
||||
import Phoenix.LiveDashboard.Router
|
||||
|
||||
# IMPORTANT: `strip_trailing_extension` in endpoint.ex removes
|
||||
# the extension from the path
|
||||
@@ -11,6 +12,7 @@ defmodule PinchflatWeb.Router do
|
||||
plug :put_root_layout, html: {PinchflatWeb.Layouts, :root}
|
||||
plug :protect_from_forgery
|
||||
plug :put_secure_browser_headers
|
||||
plug :allow_iframe_embed
|
||||
end
|
||||
|
||||
pipeline :api do
|
||||
@@ -45,21 +47,12 @@ defmodule PinchflatWeb.Router do
|
||||
get "/media/:uuid/stream", MediaItems.MediaItemController, :stream
|
||||
end
|
||||
|
||||
# Enable LiveDashboard and Swoosh mailbox preview in development
|
||||
if Application.compile_env(:pinchflat, :dev_routes) do
|
||||
# If you want to use the LiveDashboard in production, you should put
|
||||
# it behind authentication and allow only admins to access it.
|
||||
# If your application does not have an admins-only section yet,
|
||||
# you can use Plug.BasicAuth to set up some basic authentication
|
||||
# as long as you are also using SSL (which you should anyway).
|
||||
import Phoenix.LiveDashboard.Router
|
||||
scope "/dev" do
|
||||
pipe_through :browser
|
||||
|
||||
scope "/dev" do
|
||||
pipe_through :browser
|
||||
|
||||
live_dashboard "/dashboard", metrics: PinchflatWeb.Telemetry
|
||||
forward "/mailbox", Plug.Swoosh.MailboxPreview
|
||||
end
|
||||
live_dashboard "/dashboard",
|
||||
metrics: PinchflatWeb.Telemetry,
|
||||
ecto_repos: [Pinchflat.Repo]
|
||||
end
|
||||
|
||||
defp maybe_basic_auth(conn, opts) do
|
||||
@@ -84,4 +77,8 @@ defmodule PinchflatWeb.Router do
|
||||
defp credential_set?(credential) do
|
||||
credential && credential != ""
|
||||
end
|
||||
|
||||
defp allow_iframe_embed(conn, _opts) do
|
||||
delete_resp_header(conn, "x-frame-options")
|
||||
end
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user