nginx sent none of the security headers REPO_POLICIES.md requires. security-headers.conf sets all six with always, so errors carry them too; nginx.conf includes it at server level and again in /assets/, whose own add_header would drop them. nginx hides the copies netwatch-server sets, so /api/ and the health check carry each header once, with nginx's value.
What the diff does not show:
The policy follows the built dist/: no inline script or style, and a data: favicon. The one inline style, the status dot's grey in src/main.js, is now a class of the same colour.
connect-src is *, not the hosts in src/main.js: the browser checks every redirect a probe follows, and the Google Cloud, Backblaze and S3 hosts redirect elsewhere. Under a list, the redirected S3 probe was blocked.
On /api/ the content security policy is now the page's, not the backend's default-src 'none', and Permissions-Policy names more features.
I ran the image with a headless browser in a container. Every kind of response (page, asset, 404, 502 with the backend down, /api/, health check) carried each header once; the sparklines filled for WAN hosts, a report reached the backend, and the browser reported no policy violation. The Hetzner and S3 Bahrain hosts did not answer from this host's network; the policy blocked nothing.
Deviation: one line of src/main.js changed, to avoid 'unsafe-inline'.
Judgement call: Referrer-Policy: no-referrer, stricter than required, as the backend already sends.
Judgement call: HSTS without preload.
Unverified: the headless browser loads no favicon; img-src data: rests on the build output.
Model: opus-5-5
nginx sent none of the security headers `REPO_POLICIES.md` requires. `security-headers.conf` sets all six with `always`, so errors carry them too; `nginx.conf` includes it at server level and again in `/assets/`, whose own `add_header` would drop them. nginx hides the copies `netwatch-server` sets, so `/api/` and the health check carry each header once, with nginx's value.
What the diff does not show:
- The policy follows the built `dist/`: no inline script or style, and a `data:` favicon. The one inline style, the status dot's grey in `src/main.js`, is now a class of the same colour.
- `connect-src` is `*`, not the hosts in `src/main.js`: the browser checks every redirect a probe follows, and the Google Cloud, Backblaze and S3 hosts redirect elsewhere. Under a list, the redirected S3 probe was blocked.
- On `/api/` the content security policy is now the page's, not the backend's `default-src 'none'`, and `Permissions-Policy` names more features.
- I ran the image with a headless browser in a container. Every kind of response (page, asset, 404, 502 with the backend down, `/api/`, health check) carried each header once; the sparklines filled for WAN hosts, a report reached the backend, and the browser reported no policy violation. The Hetzner and S3 Bahrain hosts did not answer from this host's network; the policy blocked nothing.
Deviation: one line of `src/main.js` changed, to avoid `'unsafe-inline'`.
Judgement call: `Referrer-Policy: no-referrer`, stricter than required, as the backend already sends.
Judgement call: HSTS without `preload`.
Unverified: the headless browser loads no favicon; `img-src data:` rests on the build output.
Model: opus-5-5
nginx sent none of the security headers REPO_POLICIES.md requires.
security-headers.conf now sets all six with always, included at server
level and again in /assets/, whose own add_header would otherwise drop
them. nginx hides the copies netwatch-server sets, so /api/ and the
health check carry each header once. The content security policy
allows no inline script or style; the host row's status dot took its
grey from a style attribute, now a class. connect-src is * because
several probed hosts redirect to other hosts and the browser checks
every redirect against it. Referrer-Policy is no-referrer, as the
backend already sends.
Model: opus-5-5
PASS: the change meets the definition of done of #18 as updated, and I found no defects in it.
Model: opus-5-5
PASS: the change meets the definition of done of https://git.eeqj.de/sneak/netwatch/issues/18 as updated, and I found no defects in it.
Model: opus-5-5
clawbot
merged commit d81da05748 into next2026-09-29 10:22:13 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
nginx sent none of the security headers
REPO_POLICIES.mdrequires.security-headers.confsets all six withalways, so errors carry them too;nginx.confincludes it at server level and again in/assets/, whose ownadd_headerwould drop them. nginx hides the copiesnetwatch-serversets, so/api/and the health check carry each header once, with nginx's value.What the diff does not show:
dist/: no inline script or style, and adata:favicon. The one inline style, the status dot's grey insrc/main.js, is now a class of the same colour.connect-srcis*, not the hosts insrc/main.js: the browser checks every redirect a probe follows, and the Google Cloud, Backblaze and S3 hosts redirect elsewhere. Under a list, the redirected S3 probe was blocked./api/the content security policy is now the page's, not the backend'sdefault-src 'none', andPermissions-Policynames more features./api/, health check) carried each header once; the sparklines filled for WAN hosts, a report reached the backend, and the browser reported no policy violation. The Hetzner and S3 Bahrain hosts did not answer from this host's network; the policy blocked nothing.Deviation: one line of
src/main.jschanged, to avoid'unsafe-inline'.Judgement call:
Referrer-Policy: no-referrer, stricter than required, as the backend already sends.Judgement call: HSTS without
preload.Unverified: the headless browser loads no favicon;
img-src data:rests on the build output.Model: opus-5-5
1819142cceto28d99e89d0PASS: the change meets the definition of done of #18 as updated, and I found no defects in it.
Model: opus-5-5