diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Refresh the server configs and drop `unsafe-inline`
The inline handlers and the auto-submitting selects are gone, so
`script-src` no longer needs it, and t0004 now checks that the three
configs pin the same policy.
Diffstat (limited to 'custom/servers/apache.conf')
| -rw-r--r-- | custom/servers/apache.conf | 60 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 26 insertions, 34 deletions
diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf index 3c035f7..bbd3e75 100644 --- a/custom/servers/apache.conf +++ b/custom/servers/apache.conf @@ -136,9 +136,9 @@ AddType text/plain .txt Require all granted # These assets rarely change, so let browsers cache them. Keep the - # caching scoped to this directory. cgit sends no caching headers of its - # own, so a server-wide ExpiresDefault would stamp freshness onto its - # pages, fight the no-store cgit puts on the login page, and could let + # caching scoped to this directory. Ordinary cgit pages carry no caching + # headers, so a server-wide ExpiresDefault would stamp freshness onto + # them, fight the no-store cgit puts on the login page, and could let # one visitor's page be served to another from a shared cache. <IfModule mod_expires.c> ExpiresActive On @@ -148,8 +148,7 @@ AddType text/plain .txt # The cgit binary. <Directory "/usr/lib/cgit"> - # Allow CGI execution here. ScriptAlias implies it, stating it makes the - # intent clear. + # Allow CGI execution here. Options +ExecCGI # Run cgit.cgi as a CGI even if it is ever reached through a plain Alias # rather than ScriptAlias. @@ -159,8 +158,8 @@ AddType text/plain .txt </Directory> -# This vhost only bounces plain HTTP up to HTTPS. It serves no cgit itself, -# every cgit directive lives in the HTTPS vhost below. To run without TLS for +# This vhost only bounces plain HTTP up to HTTPS. It serves no cgit itself. +# Every cgit directive lives in the HTTPS vhost below. To run without TLS for # now, convert the HTTPS vhost to port 80 and delete this whole block rather # than editing it, since deleting only the Redirect line would leave a vhost # that serves nothing. @@ -205,27 +204,25 @@ AddType text/plain .txt # Site-wide security headers are set here so they also cover the static # assets Apache serves. cgit itself sends only the headers the proxy # cannot supply. Those are Status, Content-Type, Content-Length and - # Content-Disposition on downloads, a no-store Cache-Control on - # unauthenticated responses, the auth filter's Set-Cookie, and on raw + # Content-Disposition on downloads, Location on redirects, a no-store + # Cache-Control on unauthenticated responses, the auth filter's + # Set-Cookie, and on raw # repository bytes a nosniff of its own next to the stricter policy # "default-src 'none'". Everything else, this policy included, is the # proxy's job. # # The word setifempty is load bearing on the two headers cgit can also # emit. "Header always set" replaces a same-named header even when the - # CGI sent it, which was verified against Apache 2.4.67 and would swap - # the strict policy on raw repository content for this looser site one. - # setifempty yields to whatever cgit sent and still covers every response - # without one, the HTML pages, the static assets, and with always also - # Apache's own error pages. Referrer-Policy stays a plain set because - # cgit never emits it, so there is nothing to overwrite. + # CGI sent it, which would swap the strict policy on raw repository + # content for this looser site one. setifempty yields to whatever cgit + # sent. Referrer-Policy stays a plain set because cgit never emits it. # - # script-src stays self because cgit loads only its own cgit.js, and - # style-src allows inline for the diffstat bars. form-action self covers - # the login form, the only form cgit renders. If you enable the gravatar - # or libravatar avatar filter, add its host to img-src, for example - # https://www.gravatar.com. - Header always setifempty Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'" + # form-action self covers the login form, the only form cgit renders. If + # you enable the gravatar or libravatar avatar filter, add its host to + # img-src, for example https://www.gravatar.com. A head-include or + # repo.head-content that injects a <style> block needs 'unsafe-inline' + # added to style-src. + Header always setifempty Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'" Header always setifempty X-Content-Type-Options "nosniff" Header always set Referrer-Policy "no-referrer" @@ -250,12 +247,10 @@ AddType text/plain .txt # once browsers have seen it. Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" - # These five files are the only things served off disk. Each Alias maps - # one URL to one file. Because they come before the ScriptAlias below, a - # request for /cgit.css is answered from disk and never reaches cgit. - # cgit.css and cgit.js are the paths cgit's HTML points at by default, so - # if you relocate the assets update both these Alias targets and the css, - # js, logo and favicon settings in cgitrc to agree. + # These five files are the only things served off disk. cgit.css and + # cgit.js are the paths cgit's HTML points at by default, so if you + # relocate the assets update both these Alias targets and the css, js, + # logo and favicon settings in cgitrc to agree. Alias /cgit.css /usr/share/cgit/cgit.css Alias /cgit.js /usr/share/cgit/cgit.js Alias /cgit.png /usr/share/cgit/cgit.png @@ -265,13 +260,10 @@ AddType text/plain .txt # ScriptAlias maps a URL prefix to a path, marks it executable, and # forwards the rest of the URL as PATH_INFO. Mapping / makes cgit the # handler for every URL the static Aliases above did not already claim. - # - # The trailing slash on cgit.cgi/ is load bearing. It tells Apache that - # cgit.cgi is the program and the rest of the URL is PATH_INFO. So a - # request for /torvalds/linux/tree/kernel?h=next runs the binary with - # PATH_INFO set to /torvalds/linux/tree/kernel and QUERY_STRING set to - # h=next. cgit derives its link base from SCRIPT_NAME, which at the domain - # root is / and needs no tuning. For a sub-path install see the note below. + # The trailing slash on cgit.cgi/ is load bearing, telling Apache that + # cgit.cgi is the program and the rest of the URL is PATH_INFO. cgit + # derives its link base from SCRIPT_NAME, which at the domain root is / + # and needs no tuning. For a sub-path install see the note below. ScriptAlias / /usr/lib/cgit/cgit.cgi/ </VirtualHost> |
