diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Refresh the server configs and drop `unsafe-inline`
The inline handlers and the auto-submitting selects are gone, so
`script-src` no longer needs it, and t0004 now checks that the three
configs pin the same policy.
Diffstat (limited to 'custom/servers/lighttpd.conf')
| -rw-r--r-- | custom/servers/lighttpd.conf | 32 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 15 insertions, 17 deletions
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf index dcfb43d..27c325d 100644 --- a/custom/servers/lighttpd.conf +++ b/custom/servers/lighttpd.conf @@ -22,10 +22,9 @@ # straight off disk and must never be routed through cgit. -# A plain assignment rather than "+=", since this config stands on its own and -# there is no distro base list to append to. mod_alias maps URL paths onto -# files, mod_setenv injects CGIT_CONFIG and the response headers, and mod_cgi -# runs cgit.cgi. Adding mod_accesslog here is what the access log below needs. +# A plain assignment rather than "+=", since this config stands on its own +# and there is no distro base list to append to. Adding mod_accesslog here +# is what the access log below needs. server.modules = ( "mod_alias", "mod_setenv", @@ -37,8 +36,8 @@ server.modules = ( server.port = 80 server.username = "http" # Debian and Ubuntu use www-data server.groupname = "http" -server.document-root = "/usr/share/cgit" # a valid docroot must exist, the - # alias rules below do the routing +server.document-root = "/usr/share/cgit" # a valid docroot must exist. The + # alias rules below do the routing. server.pid-file = "/run/lighttpd.pid" server.errorlog = "/var/log/lighttpd/error.log" accesslog.filename = "/var/log/lighttpd/access.log" @@ -76,8 +75,9 @@ $HTTP["host"] == "git.example.org" { # Site-wide security headers are set here so they also cover the static # assets lighttpd serves. cgit itself sends only the headers the server # cannot supply. Those are Status, Content-Type, Content-Length and - # Content-Disposition on downloads, a no-store Cache-Control on - # unauthenticated responses, the auth filter's Set-Cookie, and on raw + # Content-Disposition on downloads, Location on redirects, a no-store + # Cache-Control on unauthenticated responses, the auth filter's + # Set-Cookie, and on raw # repository bytes a nosniff of its own next to the stricter policy # "default-src 'none'". Everything else, this policy included, is the # server's job. @@ -89,10 +89,10 @@ $HTTP["host"] == "git.example.org" { # what cgit sent, swapping the strict policy on raw repository content # for this looser site one. Never switch add to set. # - # script-src stays self because cgit loads only its own cgit.js, and - # style-src allows inline for the diffstat bars. form-action self covers - # the login form, the only form cgit renders. If you enable the gravatar - # or libravatar avatar filter, add its host to img-src. + # form-action self covers the login form, the only form cgit renders. If + # you enable the gravatar or libravatar avatar filter, add its host to + # img-src. A head-include or repo.head-content that injects a <style> + # block needs 'unsafe-inline' added to style-src. # # Permissions-Policy refuses the browser features a git viewer never asks # for, camera and location among them, for everything served here, @@ -104,7 +104,7 @@ $HTTP["host"] == "git.example.org" { # Cross-Origin-Embedder-Policy is deliberately absent because it would # break the avatar filters mentioned above. setenv.add-response-header = ( - "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'", + "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'", "X-Content-Type-Options" => "nosniff", "Referrer-Policy" => "no-referrer", "Permissions-Policy" => "accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()", @@ -116,10 +116,8 @@ $HTTP["host"] == "git.example.org" { # it is hard to undo once browsers have seen it. #setenv.add-response-header += ( "Strict-Transport-Security" => "max-age=63072000; includeSubDomains" ) - # Register the cgit binary as a CGI program. The key cgit.cgi matches the - # binary's name and the empty value means the file is itself the program, - # with no interpreter in front of it. This is what makes lighttpd split - # the trailing path off as PATH_INFO, so never drop it. + # Register the cgit binary as a CGI program. The empty value means the + # file is itself the program rather than input to an interpreter. cgi.assign = ( "cgit.cgi" => "" ) # Routing. lighttpd's alias.url is first-match in declaration order, not |
