X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/735b8c256a6fbaff6b8da48b41b21d9d12f05582..dafd66c2a336939739ee773b5dd3c65b69042fbb:/apps/workbench/config/application.default.yml diff --git a/apps/workbench/config/application.default.yml b/apps/workbench/config/application.default.yml index e7b736618e..239ffcd225 100644 --- a/apps/workbench/config/application.default.yml +++ b/apps/workbench/config/application.default.yml @@ -214,7 +214,7 @@ common: enable_public_projects_page: true # by default, disable the "Getting Started" popup which is specific to the public beta install - enable_getting_started_popup: true + enable_getting_started_popup: false # Ask Arvados API server to compress its response payloads. api_response_compression: true @@ -257,3 +257,18 @@ common: # Example: # keep_web_download_url: https://download.uuid_prefix.arvadosapi.com/c=%{uuid_or_pdh} keep_web_download_url: false + + # In "trust all content" mode, Workbench will redirect download + # requests to keep-web, even in the cases when keep-web would have + # to expose XSS vulnerabilities in order to handle the redirect. + # + # When enabling this setting, the -trust-all-content flag on the + # keep-web server must also be enabled. For more detail, see + # https://godoc.org/github.com/curoverse/arvados/services/keep-web + # + # This setting has no effect in the recommended configuration, where + # the host part of keep_web_url begins with %{uuid_or_pdh}: in this + # case XSS protection is provided by browsers' same-origin policy. + # + # The default setting (false) is appropriate for a multi-user site. + trust_all_content: false