Remove redundant frame ancestors log from middleware

The log message was printed on every request when allowed ancestors
were configured, creating unnecessary noise in the logs.
This commit is contained in:
Dmitry Verkhoturov
2025-12-04 11:15:06 -06:00
committed by Umputun
parent 9132a6158b
commit bc612ddf81
-1
View File
@@ -628,7 +628,6 @@ func securityHeadersMiddleware(imageProxyEnabled bool, allowedAncestors []string
}
frameAncestors := "*"
if len(allowedAncestors) > 0 {
log.Printf("[INFO] frame embedding allowed from %+v only", allowedAncestors)
frameAncestors = strings.Join(allowedAncestors, " ")
}
w.Header().Set("Content-Security-Policy", fmt.Sprintf("default-src 'none'; base-uri 'none'; form-action 'none'; connect-src 'self'; frame-src 'self' mailto:; img-src %s; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; font-src data:; object-src 'none'; frame-ancestors %s;", imgSrc, frameAncestors))