diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Rework the response headers in the server configs
Diffstat (limited to 'custom/servers/apache.conf')
-rw-r--r--custom/servers/apache.conf60
1 file changed, 49 insertions, 11 deletions
diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf
index 4345a9e..3c035f7 100644
--- a/custom/servers/apache.conf
+++ b/custom/servers/apache.conf
@@ -175,8 +175,9 @@ AddType text/plain .txt
# The vhost that serves cgit. To run without TLS for now, change this opening
-# line to port 80, delete the SSL lines, and delete the vhost above so there
-# is only one. Everything else stays as it is.
+# line to port 80, delete the SSL lines, delete the Strict-Transport-Security
+# line, and delete the vhost above so there is only one. Everything else stays
+# as it is.
<VirtualHost *:443>
ServerName git.example.org
@@ -201,16 +202,53 @@ AddType text/plain .txt
# it stops after 4096 bytes. Nothing else here accepts an upload.
LimitRequestBody 65536
- # Security headers are set here, not in cgit, so they also cover the static
- # assets Apache serves. script-src stays self because cgit loads only its
- # own cgit.js, and style-src allows inline for the diffstat bars. If you
- # enable the gravatar or libravatar avatar filter, add its host to img-src,
- # for example https://www.gravatar.com.
- Header always set Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'"
- Header always set X-Content-Type-Options "nosniff"
+ # Site-wide security headers are set here so they also cover the static
+ # assets Apache serves. cgit itself sends only the headers the proxy
+ # cannot supply. Those are Status, Content-Type, Content-Length and
+ # Content-Disposition on downloads, a no-store Cache-Control on
+ # unauthenticated responses, the auth filter's Set-Cookie, and on raw
+ # repository bytes a nosniff of its own next to the stricter policy
+ # "default-src 'none'". Everything else, this policy included, is the
+ # proxy's job.
+ #
+ # The word setifempty is load bearing on the two headers cgit can also
+ # emit. "Header always set" replaces a same-named header even when the
+ # CGI sent it, which was verified against Apache 2.4.67 and would swap
+ # the strict policy on raw repository content for this looser site one.
+ # setifempty yields to whatever cgit sent and still covers every response
+ # without one, the HTML pages, the static assets, and with always also
+ # Apache's own error pages. Referrer-Policy stays a plain set because
+ # cgit never emits it, so there is nothing to overwrite.
+ #
+ # script-src stays self because cgit loads only its own cgit.js, and
+ # style-src allows inline for the diffstat bars. form-action self covers
+ # the login form, the only form cgit renders. If you enable the gravatar
+ # or libravatar avatar filter, add its host to img-src, for example
+ # https://www.gravatar.com.
+ Header always setifempty Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'"
+ Header always setifempty X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "no-referrer"
- # Enable only once you serve HTTPS exclusively, since it is hard to undo.
- #Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
+
+ # The browser features a git viewer never asks for, camera and location
+ # among them, are refused outright for everything served here, repository
+ # files included.
+ Header always set Permissions-Policy "accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()"
+
+ # Cross-origin isolation. The opener policy cuts any window.opener link
+ # between cgit and pages that open it, and the resource policy stops
+ # other origins from embedding what cgit serves, a hotlinked raw file for
+ # example. git clients are not browsers and ignore both, so clone and
+ # snapshot downloads keep working. The stricter
+ # Cross-Origin-Embedder-Policy is deliberately absent because it would
+ # break the avatar filters mentioned above.
+ Header always set Cross-Origin-Opener-Policy "same-origin"
+ Header always set Cross-Origin-Resource-Policy "same-origin"
+
+ # Two years of forced HTTPS. This config already redirects every plain
+ # request to TLS, so browsers may as well stop asking. Delete this line
+ # if you convert the vhost to plain HTTP, and know it is hard to undo
+ # once browsers have seen it.
+ Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
# These five files are the only things served off disk. Each Alias maps
# one URL to one file. Because they come before the ScriptAlias below, a