Dashboards: Add dashboard embed route (#69596)
* Dashboard embed: Set up route * Dashboard embed: Cleanup * Dashboard embed: Separate routes * Dashboard embed: Render dashboard page * Dashboard embed: Add toolbar * Dashboard embed: Send JSON on save * Dashboard embed: Add JSON param * Dashboard embed: Make the dashboard editable * Fix sending dashboard to remote server * Add notifications * Add "dashboardEmbed" feature toggle * Use the toggle * Update toggles * Add toggle on backend * Add get JSON endpoint * Add drawer * Close drawer on success * Update toggles * Cleanup * Update toggle * Allow embedding for the d-embed url * Allow embedding via custom X-Allow-Embedding header * Use callbackUrl * Cleanup * Update public/app/features/dashboard/containers/EmbeddedDashboardPage.tsx Co-authored-by: kay delaney <45561153+kaydelaney@users.noreply.github.com> * Use theme for spacing * Update toggles * Update public/app/features/dashboard/components/EmbeddedDashboard/SaveDashboardForm.tsx Co-authored-by: Polina Boneva <13227501+polibb@users.noreply.github.com> * Add select data source modal --------- Co-authored-by: kay delaney <45561153+kaydelaney@users.noreply.github.com> Co-authored-by: Polina Boneva <13227501+polibb@users.noreply.github.com>
This commit is contained in:
co-authored by
kay delaney
Polina Boneva
parent
a8d2a9ae2b
commit
420b19e0e4
@@ -52,7 +52,10 @@ func AddDefaultResponseHeaders(cfg *setting.Cfg) web.Handler {
|
||||
addNoCacheHeaders(c.Resp)
|
||||
}
|
||||
|
||||
if !cfg.AllowEmbedding {
|
||||
// X-Allow-Embedding header is set for specific URLs that need to be embedded in an iframe regardless
|
||||
// of the configured allow_embedding setting.
|
||||
embeddingHeader := w.Header().Get("X-Allow-Embedding")
|
||||
if !cfg.AllowEmbedding && embeddingHeader != "allow" {
|
||||
addXFrameOptionsDenyHeader(w)
|
||||
}
|
||||
addSecurityHeaders(w, cfg)
|
||||
@@ -60,6 +63,14 @@ func AddDefaultResponseHeaders(cfg *setting.Cfg) web.Handler {
|
||||
}
|
||||
}
|
||||
|
||||
func AddAllowEmbeddingHeader() web.Handler {
|
||||
return func(c *web.Context) {
|
||||
c.Resp.Before(func(w web.ResponseWriter) {
|
||||
w.Header().Set("X-Allow-Embedding", "allow")
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// addSecurityHeaders adds HTTP(S) response headers that enable various security protections in the client's browser.
|
||||
func addSecurityHeaders(w web.ResponseWriter, cfg *setting.Cfg) {
|
||||
if cfg.StrictTransportSecurity {
|
||||
|
||||
Reference in New Issue
Block a user