diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Rework the response headers in the server configs
Diffstat (limited to 'custom/servers/lighttpd.conf')
-rw-r--r--custom/servers/lighttpd.conf46
1 file changed, 38 insertions, 8 deletions
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf
index 6ae87e0..dcfb43d 100644
--- a/custom/servers/lighttpd.conf
+++ b/custom/servers/lighttpd.conf
@@ -73,17 +73,47 @@ $HTTP["host"] == "git.example.org" {
# the same path used here, but setting it makes the location explicit.
setenv.add-environment = ( "CGIT_CONFIG" => "/etc/cgitrc" )
- # Security headers are set here, not in cgit, so they also cover the
- # static assets lighttpd serves. script-src stays self because cgit loads
- # only its own cgit.js, and style-src allows inline for the diffstat bars.
- # If you enable the gravatar or libravatar avatar filter, add its host to
- # img-src.
+ # Site-wide security headers are set here so they also cover the static
+ # assets lighttpd serves. cgit itself sends only the headers the server
+ # cannot supply. Those are Status, Content-Type, Content-Length and
+ # Content-Disposition on downloads, a no-store Cache-Control on
+ # unauthenticated responses, the auth filter's Set-Cookie, and on raw
+ # repository bytes a nosniff of its own next to the stricter policy
+ # "default-src 'none'". Everything else, this policy included, is the
+ # server's job.
+ #
+ # The add in add-response-header is load bearing. It appends a second
+ # copy next to what cgit emitted, so a raw page carries both policies and
+ # the browser enforces the stricter one, while the doubled nosniff line
+ # is harmless. The set-response-header directive would instead replace
+ # what cgit sent, swapping the strict policy on raw repository content
+ # for this looser site one. Never switch add to set.
+ #
+ # script-src stays self because cgit loads only its own cgit.js, and
+ # style-src allows inline for the diffstat bars. form-action self covers
+ # the login form, the only form cgit renders. If you enable the gravatar
+ # or libravatar avatar filter, add its host to img-src.
+ #
+ # Permissions-Policy refuses the browser features a git viewer never asks
+ # for, camera and location among them, for everything served here,
+ # repository files included. The opener policy cuts any window.opener
+ # link between cgit and pages that open it, and the resource policy stops
+ # other origins from embedding what cgit serves, a hotlinked raw file for
+ # example. git clients are not browsers and ignore both, so clone and
+ # snapshot downloads keep working. The stricter
+ # Cross-Origin-Embedder-Policy is deliberately absent because it would
+ # break the avatar filters mentioned above.
setenv.add-response-header = (
- "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'",
+ "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'",
"X-Content-Type-Options" => "nosniff",
- "Referrer-Policy" => "no-referrer"
+ "Referrer-Policy" => "no-referrer",
+ "Permissions-Policy" => "accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()",
+ "Cross-Origin-Opener-Policy" => "same-origin",
+ "Cross-Origin-Resource-Policy" => "same-origin"
)
- # Enable only once you serve HTTPS exclusively, since it is hard to undo.
+ # Two years of forced HTTPS. Enable this together with the TLS socket at
+ # the end of this file and only once you serve HTTPS exclusively, since
+ # it is hard to undo once browsers have seen it.
#setenv.add-response-header += ( "Strict-Transport-Security" => "max-age=63072000; includeSubDomains" )
# Register the cgit binary as a CGI program. The key cgit.cgi matches the