diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Rework the response headers in the server configs
Diffstat (limited to 'custom/servers/lighttpd.conf')
| -rw-r--r-- | custom/servers/lighttpd.conf | 46 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 38 insertions, 8 deletions
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf index 6ae87e0..dcfb43d 100644 --- a/custom/servers/lighttpd.conf +++ b/custom/servers/lighttpd.conf @@ -73,17 +73,47 @@ $HTTP["host"] == "git.example.org" { # the same path used here, but setting it makes the location explicit. setenv.add-environment = ( "CGIT_CONFIG" => "/etc/cgitrc" ) - # Security headers are set here, not in cgit, so they also cover the - # static assets lighttpd serves. script-src stays self because cgit loads - # only its own cgit.js, and style-src allows inline for the diffstat bars. - # If you enable the gravatar or libravatar avatar filter, add its host to - # img-src. + # Site-wide security headers are set here so they also cover the static + # assets lighttpd serves. cgit itself sends only the headers the server + # cannot supply. Those are Status, Content-Type, Content-Length and + # Content-Disposition on downloads, a no-store Cache-Control on + # unauthenticated responses, the auth filter's Set-Cookie, and on raw + # repository bytes a nosniff of its own next to the stricter policy + # "default-src 'none'". Everything else, this policy included, is the + # server's job. + # + # The add in add-response-header is load bearing. It appends a second + # copy next to what cgit emitted, so a raw page carries both policies and + # the browser enforces the stricter one, while the doubled nosniff line + # is harmless. The set-response-header directive would instead replace + # what cgit sent, swapping the strict policy on raw repository content + # for this looser site one. Never switch add to set. + # + # script-src stays self because cgit loads only its own cgit.js, and + # style-src allows inline for the diffstat bars. form-action self covers + # the login form, the only form cgit renders. If you enable the gravatar + # or libravatar avatar filter, add its host to img-src. + # + # Permissions-Policy refuses the browser features a git viewer never asks + # for, camera and location among them, for everything served here, + # repository files included. The opener policy cuts any window.opener + # link between cgit and pages that open it, and the resource policy stops + # other origins from embedding what cgit serves, a hotlinked raw file for + # example. git clients are not browsers and ignore both, so clone and + # snapshot downloads keep working. The stricter + # Cross-Origin-Embedder-Policy is deliberately absent because it would + # break the avatar filters mentioned above. setenv.add-response-header = ( - "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'", + "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'", "X-Content-Type-Options" => "nosniff", - "Referrer-Policy" => "no-referrer" + "Referrer-Policy" => "no-referrer", + "Permissions-Policy" => "accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()", + "Cross-Origin-Opener-Policy" => "same-origin", + "Cross-Origin-Resource-Policy" => "same-origin" ) - # Enable only once you serve HTTPS exclusively, since it is hard to undo. + # Two years of forced HTTPS. Enable this together with the TLS socket at + # the end of this file and only once you serve HTTPS exclusively, since + # it is hard to undo once browsers have seen it. #setenv.add-response-header += ( "Strict-Transport-Security" => "max-age=63072000; includeSubDomains" ) # Register the cgit binary as a CGI program. The key cgit.cgi matches the |
