diff --git a/access_gate.go b/access_gate.go index 586ccab..5fbd680 100644 --- a/access_gate.go +++ b/access_gate.go @@ -177,8 +177,10 @@ func (g AccessGate) normalized() *AccessGate { func (g *AccessGate) writeDenied(w http.ResponseWriter, r *http.Request) { if acceptsHTML(r.Header.Get("Accept")) { + // 200 so AppAPI's proxy CSP keeps frame-ancestors 'self' and the ExApp + // iframe can show the message (403 responses get frame-ancestors 'none'). w.Header().Set("Content-Type", "text/html; charset=utf-8") - w.WriteHeader(http.StatusForbidden) + w.WriteHeader(http.StatusOK) _, _ = w.Write(deniedHTML) return } @@ -216,7 +218,19 @@ var defaultSkipPaths = []string{"/heartbeat", "/enabled", "/init"} var deniedHTML = []byte(` -Access denied -

Access denied

You are not a member of a required group for this app.

+ + + Access denied + + + +

Access denied

+

You are not a member of a required group for this app. Ask an administrator to add you to the group if you need access.

+ `) diff --git a/access_gate_test.go b/access_gate_test.go index f098151..90ba7bd 100644 --- a/access_gate_test.go +++ b/access_gate_test.go @@ -159,7 +159,7 @@ func TestAccessGateDeniesNonMemberWithHTML(t *testing.T) { req.Header.Set("Accept", "text/html,application/xhtml+xml") rec := httptest.NewRecorder() h.ServeHTTP(rec, req) - if rec.Code != http.StatusForbidden { + if rec.Code != http.StatusOK { t.Fatalf("got %d", rec.Code) } if !strings.Contains(rec.Header().Get("Content-Type"), "text/html") {