diff options
context:
space:
mode:
Diffstat (limited to 'custom/servers/apache.conf')
-rw-r--r--custom/servers/apache.conf10
1 file changed, 5 insertions, 5 deletions
diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf
index f25c444..d95d76f 100644
--- a/custom/servers/apache.conf
+++ b/custom/servers/apache.conf
@@ -204,11 +204,11 @@ AddType text/plain .txt
# Site-wide security headers are set here so they also cover the static
# assets Apache serves. cgit itself sends only the headers the proxy
# cannot supply. Those are Status, Content-Type, Content-Length and
- # Content-Disposition on downloads, Location on redirects, a no-store
- # Cache-Control on unauthenticated responses, the auth filter's Set-Cookie,
- # and on raw repository bytes a nosniff of its own next to the stricter
- # policy "default-src 'none'". Everything else, this policy included, is
- # the proxy's job.
+ # Content-Disposition on downloads, Location on redirects, a Cache-Control
+ # marking the login page no-store and a page behind an auth filter private,
+ # the auth filter's Set-Cookie, and on raw repository bytes a nosniff of
+ # its own next to the stricter policy "default-src 'none'". Everything
+ # else, this policy included, is the proxy's job.
#
# The word setifempty is load bearing on the two headers cgit can also
# emit. "Header always set" replaces a same-named header even when the