aprs.me/lib/aprsme_web/endpoint.ex
Graham McInitre 243a98df77 fix: security hardening and query performance improvements
- Session cookie: add encryption_salt and secure flag to endpoint
- CSP: remove unsafe-eval from script-src directive
- /metrics: wrap PromEx endpoint behind rate-limited pipeline
- LiveView signing_salt: move to env var in production config
- LiveView performance: defer heavy aggregation queries past initial mount
- SQL: replace correlated subquery with DISTINCT ON in get_heard_by_stations
2026-07-21 10:13:30 -05:00

80 lines
2.4 KiB
Elixir

defmodule AprsmeWeb.Endpoint do
@moduledoc false
use Phoenix.Endpoint, otp_app: :aprsme
# The session will be stored in the cookie and signed,
# this means its contents can be read but not tampered with.
# Set :encryption_salt if you would also like to encrypt it.
@default_session_options [
store: :cookie,
key: "_aprs_key",
signing_salt: "0toQ/Ejk",
encryption_salt: "local-dev-only-encryption-salt",
secure: false,
same_site: "Lax"
]
# Computed at compile-time by merging defaults with any endpoint config
@session_options Keyword.merge(
@default_session_options,
:aprsme
|> Application.compile_env(AprsmeWeb.Endpoint, [])
|> Keyword.get(:session_options, [])
)
def session_options, do: @session_options
socket "/live", Phoenix.LiveView.Socket,
websocket: [connect_info: [session: @session_options], timeout: 60_000],
longpoll: [connect_info: [session: @session_options]]
# Mobile API socket for iOS/Android apps
socket "/mobile", AprsmeWeb.MobileUserSocket,
websocket: [timeout: 60_000],
longpoll: false
# Serve at "/" the static files from "priv/static" directory.
#
# You should set gzip to true if you are running phx.digest
# when deploying your static files in production.
plug Plug.Static,
at: "/",
from: :aprsme,
gzip: true,
only: ~w(assets fonts images aprs-symbols favicon.ico robots.txt)
if Mix.env() == :dev do
plug Tidewave
end
# Code reloading can be explicitly enabled under the
# :code_reloader configuration of your endpoint.
if code_reloading? do
socket "/phoenix/live_reload/socket", Phoenix.LiveReloader.Socket
plug Phoenix.LiveReloader
plug Phoenix.CodeReloader
plug Phoenix.Ecto.CheckRepoStatus, otp_app: :aprsme
end
plug Phoenix.LiveDashboard.RequestLogger,
param_key: "request_logger",
cookie_key: "request_logger"
plug AprsmeWeb.Plugs.RemoteIp
plug Plug.RequestId
plug Plug.Telemetry, event_prefix: [:phoenix, :endpoint], log: {AprsmeWeb.Plugs.LogFilter, :log_level, []}
plug Plug.Parsers,
parsers: [:urlencoded, :multipart, :json],
pass: ["*/*"],
json_decoder: Phoenix.json_library()
plug Plug.MethodOverride
plug Plug.Head
plug Plug.Session, @session_options
# Health check endpoint
plug AprsmeWeb.Plugs.HealthCheck
plug AprsmeWeb.Router
end