nginx: security headers on every response (closes #18)
check / check (push) Successful in 21s
check / check (push) Successful in 21s
nginx sent none of the security headers REPO_POLICIES.md requires. security-headers.conf now sets all six with always, included at server level and again in /assets/, whose own add_header would otherwise drop them. nginx hides the copies netwatch-server sets, so /api/ and the health check carry each header once. The content security policy allows no inline script or style; the host row's status dot took its grey from a style attribute, now a class. connect-src is * because several probed hosts redirect to other hosts and the browser checks every redirect against it. Referrer-Policy is no-referrer, as the backend already sends. Model: opus-5-5
This commit was merged in pull request #70.
This commit is contained in:
@@ -72,6 +72,7 @@ RUN addgroup -g 1000 -S netwatch && \
|
||||
# conf.d; bin/entrypoint.sh says how.
|
||||
RUN rm /etc/nginx/conf.d/default.conf
|
||||
COPY nginx.conf /etc/nginx/templates/netwatch.conf.template
|
||||
COPY security-headers.conf /etc/nginx/security-headers.conf
|
||||
COPY --from=frontend /app/dist /usr/share/nginx/html
|
||||
COPY --from=builder /src/netwatch-server /usr/local/bin/netwatch-server
|
||||
COPY bin/entrypoint.sh /usr/local/bin/entrypoint.sh
|
||||
|
||||
Reference in New Issue
Block a user