Skip to content

Conversation

@at88mph
Copy link
Member

@at88mph at88mph commented Jan 12, 2026

Use Case

In order to support embedded session support in the Science Gateway (https://gateway.srcnet.skao.int), the custom-security-policy header will be sent to specifically allow the Session to be run inside an iFrame:
https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Content-Security-Policy

Changes

  • New configuration added to support a deployment.skaha.sessions.ingress.customResponseHeaders map
  • Modified configuration (backward compatible) to move deployment.skaha.session.tls to deployment.skaha.sessions.ingress.tls with warning message
  • New Middleware is created if customResponseHeaders created. All User Session IngressRoute objects configured to use it if enabled.

CADC-15041

@at88mph at88mph requested a review from shinybrar January 12, 2026 20:22
@github-actions
Copy link
Contributor

github-actions bot commented Jan 12, 2026

✅ All pre-commit checks passed

Thanks for keeping the repo tidy! ✨

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants