diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Refresh the server configs and drop `unsafe-inline`
The inline handlers and the auto-submitting selects are gone, so `script-src` no longer needs it, and t0004 now checks that the three configs pin the same policy.
Diffstat (limited to 'custom/servers/apache.conf')
-rw-r--r--custom/servers/apache.conf60
1 file changed, 26 insertions, 34 deletions
diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf
index 3c035f7..bbd3e75 100644
--- a/custom/servers/apache.conf
+++ b/custom/servers/apache.conf
@@ -136,9 +136,9 @@ AddType text/plain .txt
Require all granted
# These assets rarely change, so let browsers cache them. Keep the
- # caching scoped to this directory. cgit sends no caching headers of its
- # own, so a server-wide ExpiresDefault would stamp freshness onto its
- # pages, fight the no-store cgit puts on the login page, and could let
+ # caching scoped to this directory. Ordinary cgit pages carry no caching
+ # headers, so a server-wide ExpiresDefault would stamp freshness onto
+ # them, fight the no-store cgit puts on the login page, and could let
# one visitor's page be served to another from a shared cache.
<IfModule mod_expires.c>
ExpiresActive On
@@ -148,8 +148,7 @@ AddType text/plain .txt
# The cgit binary.
<Directory "/usr/lib/cgit">
- # Allow CGI execution here. ScriptAlias implies it, stating it makes the
- # intent clear.
+ # Allow CGI execution here.
Options +ExecCGI
# Run cgit.cgi as a CGI even if it is ever reached through a plain Alias
# rather than ScriptAlias.
@@ -159,8 +158,8 @@ AddType text/plain .txt
</Directory>
-# This vhost only bounces plain HTTP up to HTTPS. It serves no cgit itself,
-# every cgit directive lives in the HTTPS vhost below. To run without TLS for
+# This vhost only bounces plain HTTP up to HTTPS. It serves no cgit itself.
+# Every cgit directive lives in the HTTPS vhost below. To run without TLS for
# now, convert the HTTPS vhost to port 80 and delete this whole block rather
# than editing it, since deleting only the Redirect line would leave a vhost
# that serves nothing.
@@ -205,27 +204,25 @@ AddType text/plain .txt
# Site-wide security headers are set here so they also cover the static
# assets Apache serves. cgit itself sends only the headers the proxy
# cannot supply. Those are Status, Content-Type, Content-Length and
- # Content-Disposition on downloads, a no-store Cache-Control on
- # unauthenticated responses, the auth filter's Set-Cookie, and on raw
+ # Content-Disposition on downloads, Location on redirects, a no-store
+ # Cache-Control on unauthenticated responses, the auth filter's
+ # Set-Cookie, and on raw
# repository bytes a nosniff of its own next to the stricter policy
# "default-src 'none'". Everything else, this policy included, is the
# proxy's job.
#
# The word setifempty is load bearing on the two headers cgit can also
# emit. "Header always set" replaces a same-named header even when the
- # CGI sent it, which was verified against Apache 2.4.67 and would swap
- # the strict policy on raw repository content for this looser site one.
- # setifempty yields to whatever cgit sent and still covers every response
- # without one, the HTML pages, the static assets, and with always also
- # Apache's own error pages. Referrer-Policy stays a plain set because
- # cgit never emits it, so there is nothing to overwrite.
+ # CGI sent it, which would swap the strict policy on raw repository
+ # content for this looser site one. setifempty yields to whatever cgit
+ # sent. Referrer-Policy stays a plain set because cgit never emits it.
#
- # script-src stays self because cgit loads only its own cgit.js, and
- # style-src allows inline for the diffstat bars. form-action self covers
- # the login form, the only form cgit renders. If you enable the gravatar
- # or libravatar avatar filter, add its host to img-src, for example
- # https://www.gravatar.com.
- Header always setifempty Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'"
+ # form-action self covers the login form, the only form cgit renders. If
+ # you enable the gravatar or libravatar avatar filter, add its host to
+ # img-src, for example https://www.gravatar.com. A head-include or
+ # repo.head-content that injects a <style> block needs 'unsafe-inline'
+ # added to style-src.
+ Header always setifempty Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'"
Header always setifempty X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "no-referrer"
@@ -250,12 +247,10 @@ AddType text/plain .txt
# once browsers have seen it.
Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
- # These five files are the only things served off disk. Each Alias maps
- # one URL to one file. Because they come before the ScriptAlias below, a
- # request for /cgit.css is answered from disk and never reaches cgit.
- # cgit.css and cgit.js are the paths cgit's HTML points at by default, so
- # if you relocate the assets update both these Alias targets and the css,
- # js, logo and favicon settings in cgitrc to agree.
+ # These five files are the only things served off disk. cgit.css and
+ # cgit.js are the paths cgit's HTML points at by default, so if you
+ # relocate the assets update both these Alias targets and the css, js,
+ # logo and favicon settings in cgitrc to agree.
Alias /cgit.css /usr/share/cgit/cgit.css
Alias /cgit.js /usr/share/cgit/cgit.js
Alias /cgit.png /usr/share/cgit/cgit.png
@@ -265,13 +260,10 @@ AddType text/plain .txt
# ScriptAlias maps a URL prefix to a path, marks it executable, and
# forwards the rest of the URL as PATH_INFO. Mapping / makes cgit the
# handler for every URL the static Aliases above did not already claim.
- #
- # The trailing slash on cgit.cgi/ is load bearing. It tells Apache that
- # cgit.cgi is the program and the rest of the URL is PATH_INFO. So a
- # request for /torvalds/linux/tree/kernel?h=next runs the binary with
- # PATH_INFO set to /torvalds/linux/tree/kernel and QUERY_STRING set to
- # h=next. cgit derives its link base from SCRIPT_NAME, which at the domain
- # root is / and needs no tuning. For a sub-path install see the note below.
+ # The trailing slash on cgit.cgi/ is load bearing, telling Apache that
+ # cgit.cgi is the program and the rest of the URL is PATH_INFO. cgit
+ # derives its link base from SCRIPT_NAME, which at the domain root is /
+ # and needs no tuning. For a sub-path install see the note below.
ScriptAlias / /usr/lib/cgit/cgit.cgi/
</VirtualHost>