diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Rework the response headers in the server configs
Diffstat (limited to 'custom/servers/apache.conf')
| -rw-r--r-- | custom/servers/apache.conf | 60 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 49 insertions, 11 deletions
diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf index 4345a9e..3c035f7 100644 --- a/custom/servers/apache.conf +++ b/custom/servers/apache.conf @@ -175,8 +175,9 @@ AddType text/plain .txt # The vhost that serves cgit. To run without TLS for now, change this opening -# line to port 80, delete the SSL lines, and delete the vhost above so there -# is only one. Everything else stays as it is. +# line to port 80, delete the SSL lines, delete the Strict-Transport-Security +# line, and delete the vhost above so there is only one. Everything else stays +# as it is. <VirtualHost *:443> ServerName git.example.org @@ -201,16 +202,53 @@ AddType text/plain .txt # it stops after 4096 bytes. Nothing else here accepts an upload. LimitRequestBody 65536 - # Security headers are set here, not in cgit, so they also cover the static - # assets Apache serves. script-src stays self because cgit loads only its - # own cgit.js, and style-src allows inline for the diffstat bars. If you - # enable the gravatar or libravatar avatar filter, add its host to img-src, - # for example https://www.gravatar.com. - Header always set Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'" - Header always set X-Content-Type-Options "nosniff" + # Site-wide security headers are set here so they also cover the static + # assets Apache serves. cgit itself sends only the headers the proxy + # cannot supply. Those are Status, Content-Type, Content-Length and + # Content-Disposition on downloads, a no-store Cache-Control on + # unauthenticated responses, the auth filter's Set-Cookie, and on raw + # repository bytes a nosniff of its own next to the stricter policy + # "default-src 'none'". Everything else, this policy included, is the + # proxy's job. + # + # The word setifempty is load bearing on the two headers cgit can also + # emit. "Header always set" replaces a same-named header even when the + # CGI sent it, which was verified against Apache 2.4.67 and would swap + # the strict policy on raw repository content for this looser site one. + # setifempty yields to whatever cgit sent and still covers every response + # without one, the HTML pages, the static assets, and with always also + # Apache's own error pages. Referrer-Policy stays a plain set because + # cgit never emits it, so there is nothing to overwrite. + # + # script-src stays self because cgit loads only its own cgit.js, and + # style-src allows inline for the diffstat bars. form-action self covers + # the login form, the only form cgit renders. If you enable the gravatar + # or libravatar avatar filter, add its host to img-src, for example + # https://www.gravatar.com. + Header always setifempty Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'" + Header always setifempty X-Content-Type-Options "nosniff" Header always set Referrer-Policy "no-referrer" - # Enable only once you serve HTTPS exclusively, since it is hard to undo. - #Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" + + # The browser features a git viewer never asks for, camera and location + # among them, are refused outright for everything served here, repository + # files included. + Header always set Permissions-Policy "accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()" + + # Cross-origin isolation. The opener policy cuts any window.opener link + # between cgit and pages that open it, and the resource policy stops + # other origins from embedding what cgit serves, a hotlinked raw file for + # example. git clients are not browsers and ignore both, so clone and + # snapshot downloads keep working. The stricter + # Cross-Origin-Embedder-Policy is deliberately absent because it would + # break the avatar filters mentioned above. + Header always set Cross-Origin-Opener-Policy "same-origin" + Header always set Cross-Origin-Resource-Policy "same-origin" + + # Two years of forced HTTPS. This config already redirects every plain + # request to TLS, so browsers may as well stop asking. Delete this line + # if you convert the vhost to plain HTTP, and know it is hard to undo + # once browsers have seen it. + Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" # These five files are the only things served off disk. Each Alias maps # one URL to one file. Because they come before the ScriptAlias below, a |
