From deec74a00a3f020c2e478199cf9a13404d290919 Mon Sep 17 00:00:00 2001 From: Kristjan ESPERANTO <35647502+KristjanESPERANTO@users.noreply.github.com> Date: Sun, 20 Sep 2026 13:18:29 +0200 Subject: [PATCH] fix: always redact client configuration --- js/defaults.js | 1 - js/node_helper.js | 2 +- js/server.js | 19 +++++++------------ js/server_functions.js | 6 +----- js/utils.js | 16 ++++++---------- tests/configs/config_variables.js | 1 - 6 files changed, 15 insertions(+), 30 deletions(-) diff --git a/js/defaults.js b/js/defaults.js index b0fa680ccb..8fbb365856 100644 --- a/js/defaults.js +++ b/js/defaults.js @@ -24,7 +24,6 @@ const defaults = { customCss: "config/custom.css", foreignModulesDir: "modules", defaultModulesDir: "defaultmodules", - hideConfigSecrets: false, // httpHeaders used by helmet, see https://helmetjs.github.io/. You can add other/more object values by overriding this in config.js, // e.g. you need to add `frameguard: false` for embedding MagicMirror in another website, see https://github.com/MagicMirrorOrg/MagicMirror/issues/2847 httpHeaders: { contentSecurityPolicy: false, crossOriginOpenerPolicy: false, crossOriginEmbedderPolicy: false, crossOriginResourcePolicy: false, originAgentCluster: false }, diff --git a/js/node_helper.js b/js/node_helper.js index 90e8ffa8e1..c34b090af2 100644 --- a/js/node_helper.js +++ b/js/node_helper.js @@ -118,7 +118,7 @@ class NodeHelper { io.of(this.name).on("connection", (socket) => { // register catch all. socket.onAny((notification, payload) => { - if (global.config?.hideConfigSecrets && payload && typeof payload === "object") { + if (payload && typeof payload === "object") { try { // Calculate exactly which secrets this module is allowed to receive const allowedSecrets = getAllowedSecrets(this.name); diff --git a/js/server.js b/js/server.js index 0c48511555..60728203f7 100644 --- a/js/server.js +++ b/js/server.js @@ -108,17 +108,12 @@ class Server { app.use(helmet(config.httpHeaders)); app.use("/js", express.static(__dirname)); - if (config.hideConfigSecrets) { - const getErrorText = (filename) => { - return `\n\n
\n\nCannot GET /config/${filename}\n\n`;
- };
- app.get("/config/config.env", (req, res) => {
- res.status(404).send(getErrorText("config.env"));
- });
- app.get("/config/config.js", (req, res) => {
- res.status(404).send(getErrorText("config.js"));
- });
- }
+ const getConfigFileError = (filename) => (req, res) => {
+ const errorText = `\n\n\n\nCannot GET /config/${filename}\n\n`;
+ res.status(404).send(errorText);
+ };
+ app.get("/config/config.env", getConfigFileError("config.env"));
+ app.get("/config/config.js", getConfigFileError("config.js"));
const directories = ["/config", "/css", "/favicon.svg", "/defaultmodules", "/modules", "/node_modules/animate.css", "/node_modules/@fontsource", "/node_modules/@fortawesome", "/node_modules/suncalc", "/translations", "/tests/configs", "/tests/mocks"];
for (const value of Object.values(vendor)) {
@@ -135,7 +130,7 @@ class Server {
const getStartup = (req, res) => res.send(startUp);
const getConfig = (req, res) => {
- const obj = config.hideConfigSecrets ? configObj.redactedConf : configObj.fullConf;
+ const obj = configObj.redactedConf;
// Functions can't survive JSON.stringify, so we wrap them in a
// tagged object { __mmFunction: "