nginx: security headers on every response (closes #18)
check / check (push) Successful in 21s
check / check (push) Successful in 21s
nginx sent none of the security headers REPO_POLICIES.md requires. security-headers.conf now sets all six with always, included at server level and again in /assets/, whose own add_header would otherwise drop them. nginx hides the copies netwatch-server sets, so /api/ and the health check carry each header once. The content security policy allows no inline script or style; the host row's status dot took its grey from a style attribute, now a class. connect-src is * because several probed hosts redirect to other hosts and the browser checks every redirect against it. Referrer-Policy is no-referrer, as the backend already sends. Model: opus-5-5
This commit was merged in pull request #70.
This commit is contained in:
@@ -64,13 +64,15 @@ main() {
|
||||
# nginx.conf is a template: the image renders it over its own
|
||||
# default.conf, with the same port and limit bin/entrypoint.sh uses.
|
||||
# The empty file it includes trusts no proxy, as bin/entrypoint.sh
|
||||
# writes it when TRUSTED_PROXIES is unset.
|
||||
# writes it when TRUSTED_PROXIES is unset. nginx.conf also includes
|
||||
# the security headers, so the page runs under the shipped policy.
|
||||
docker run -d --rm --name "$SERVER" \
|
||||
--network "$NETWORK" --network-alias netwatch \
|
||||
-e PORT=8080 -e NGINX_ENVSUBST_FILTER='^PORT$' \
|
||||
-v "$ROOT/dist:/usr/share/nginx/html:ro" \
|
||||
-v "$ROOT/nginx.conf:/etc/nginx/templates/default.conf.template:ro" \
|
||||
-v /dev/null:/etc/nginx/trusted-proxies.conf:ro \
|
||||
-v "$ROOT/security-headers.conf:/etc/nginx/security-headers.conf:ro" \
|
||||
"$SERVER_IMAGE" > /dev/null
|
||||
|
||||
# The image's own entrypoint already exposes CDP on 9222 and passes
|
||||
|
||||
Reference in New Issue
Block a user