mirror of https://github.com/docusealco/docuseal
master
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.1
1.9.10
1.9.2
1.9.3
1.9.4
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.5.0
2.5.1
2.5.2
2.5.3
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
${ noResults }
4 Commits (e59c8b421e47ebf3ae8c36f2ca2be7e3cc9a05d0)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
f4324122cc |
Self-hosted embed: JWT shim + Rails-side glue for cross-origin iframe
Lets the EnWella EHR mount <docuseal-builder> (and -form) without a
paid Pro license. Upstream's `EmbedScriptsController` returns an
"Upgrade to Pro" stub; we override it via the static-asset path so the
real shim wins without touching the controller.
JS shim (public/js/builder.js)
- Web component that decodes the JWT minted by the embedder (`name`,
`document_urls`, `external_id`, optional `template_id`).
- Iframes /templates/:id/edit for existing templates, /new?... for the
upload-from-URL flow.
- Relays a `save` postMessage from the inner builder up as a DOM
`CustomEvent('save')` on the outer element so @docuseal/react's
onSave callback fires.
- Discovers host from its own <script src> so embedders don't have to
set data-host. JWT signature not re-verified (session cookies +
shared HMAC at the calling app are authoritative).
Builder (app/javascript/template_builder/builder.vue)
- isEmbedded computed (window.parent !== window).
- Hide #title_container in embed (sheet already shows the consent name).
- Fire the `save` postMessage at the end of the manual SAVE handler so
the outer shim can dispatch the DOM event.
Rails glue
- application_controller.rb / config/application.rb: when
EMBED_ALLOWED_ORIGIN is set, add `frame-ancestors 'self' <origin>`
to the per-request CSP and drop the default `X-Frame-Options:
SAMEORIGIN` header (different scheme/host/port = different origin,
so SAMEORIGIN blocks the EHR's iframe even in same-domain prod).
- templates_uploads_controller.rb: persist `external_id` from the
upload params so the host app can later look the template up via
`GET /api/templates?external_id=...` (deterministic fallback link
path when the `template.created` webhook doesn't reach us).
- templates_uploads_controller.rb: skip the SSRF guard when fetching
documents in development — it rejects http / non-443 / localhost,
which is exactly the Active Storage URLs the EHR sends from
https://localhost:3000.
- templates_uploads/show.html.erb: carry `external_id` through the
resubmit form (used on the encrypted-PDF prompt path).
Local HTTPS dev (puma.rb, Procfile.dev, .env.example)
- Bind ssl://0.0.0.0:PORT when LOCAL_HTTPS_CERT/KEY are set (wired by
../bin/docuseal-dev to ../.certs/lvh.me.pem). EHR runs HTTPS too,
so HTTPS iframe avoids mixed-content blocking.
- Procfile.dev runs `puma -C config/puma.rb` directly so the ssl bind
applies.
- SSL_CERT_FILE example for trusting the mkcert root so DocuSeal's
outbound HTTPS to Rails (Active Storage downloads) verifies.
|
3 months ago |
|
|
4f50df8f76 |
Dev: env-driven PORT, ruby ~> 4.0, dotenv example
|
3 months ago |
|
|
8a6430f117 |
add Dockerfile and configure production app
|
3 years ago |
|
|
97c462ead2 |
initial commit
|
3 years ago |