nginx: security headers on every response (closes #18)
check / check (push) Successful in 21s
check / check (push) Successful in 21s
nginx sent none of the security headers REPO_POLICIES.md requires. security-headers.conf now sets all six with always, included at server level and again in /assets/, whose own add_header would otherwise drop them. nginx hides the copies netwatch-server sets, so /api/ and the health check carry each header once. The content security policy allows no inline script or style; the host row's status dot took its grey from a style attribute, now a class. connect-src is * because several probed hosts redirect to other hosts and the browser checks every redirect against it. Referrer-Policy is no-referrer, as the backend already sends. Model: opus-5-5
This commit was merged in pull request #70.
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
# The security headers REPO_POLICIES.md requires on every response.
|
||||
# nginx.conf includes this file, which Dockerfile copies to
|
||||
# /etc/nginx/security-headers.conf. always sends each header on error
|
||||
# responses too.
|
||||
|
||||
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||
|
||||
# Scripts and styles load only from the page's own origin. Inline ones
|
||||
# are blocked, style attributes in markup included, so style elements
|
||||
# through classes or element.style. data: images are for the favicon
|
||||
# in index.html. connect-src is * because the browser checks each probe in
|
||||
# src/main.js against it, and also every redirect the probe follows,
|
||||
# and several of those hosts redirect to others; a list of hosts here
|
||||
# would block those probes. It also covers the reports the page sends
|
||||
# to its own origin.
|
||||
add_header Content-Security-Policy "default-src 'self'; connect-src *; img-src 'self' data:; object-src 'none'; base-uri 'none'; form-action 'none'; frame-ancestors 'none'" always;
|
||||
|
||||
add_header X-Frame-Options DENY always;
|
||||
add_header X-Content-Type-Options nosniff always;
|
||||
|
||||
# The probed hosts are not told where the page is served from.
|
||||
add_header Referrer-Policy no-referrer always;
|
||||
|
||||
add_header Permissions-Policy "accelerometer=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), usb=()" always;
|
||||
Reference in New Issue
Block a user