nginx: security headers on every response (closes #18)
check / check (push) Successful in 1m43s
check / check (push) Successful in 1m43s
nginx sent none of the security headers REPO_POLICIES.md requires. security-headers.conf now sets all six with always, included at server level and again in /assets/, whose own add_header would otherwise drop them. nginx hides the copies netwatch-server sets, so /api/ and the health check carry each header once. The content security policy allows no inline script or style; the host row's status dot took its grey from a style attribute, now a class. connect-src is * because several probed hosts redirect to other hosts and the browser checks every redirect against it. Referrer-Policy is no-referrer, as the backend already sends. Model: opus-5-5
This commit is contained in:
@@ -23,6 +23,13 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: nginx sends the security headers `REPO_POLICIES.md` requires on
|
||||
every response (issue #18), including errors, `/assets/` and what it passes on
|
||||
from the backend, whose own copies it drops so each header goes out once. They
|
||||
live in `security-headers.conf`, which `nginx.conf` includes. The content
|
||||
security policy allows no inline script or style, so the status dot's grey in
|
||||
`src/main.js` is now a class; `connect-src` is `*` because probed hosts
|
||||
redirect to others, and the browser checks each redirect against it
|
||||
- 2026-09-29: nginx takes the client address from `X-Forwarded-For` only on
|
||||
requests from the reverse proxies named in the container's `TRUSTED_PROXIES`
|
||||
(issue #64), and by default from none, where it trusted every RFC1918 address
|
||||
|
||||
Reference in New Issue
Block a user