diff options
context:
space:
mode:
Diffstat (limited to 'custom/servers/lighttpd.conf')
-rw-r--r--custom/servers/lighttpd.conf32
1 file changed, 15 insertions, 17 deletions
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf
index dcfb43d..27c325d 100644
--- a/custom/servers/lighttpd.conf
+++ b/custom/servers/lighttpd.conf
@@ -22,10 +22,9 @@
# straight off disk and must never be routed through cgit.
-# A plain assignment rather than "+=", since this config stands on its own and
-# there is no distro base list to append to. mod_alias maps URL paths onto
-# files, mod_setenv injects CGIT_CONFIG and the response headers, and mod_cgi
-# runs cgit.cgi. Adding mod_accesslog here is what the access log below needs.
+# A plain assignment rather than "+=", since this config stands on its own
+# and there is no distro base list to append to. Adding mod_accesslog here
+# is what the access log below needs.
server.modules = (
"mod_alias",
"mod_setenv",
@@ -37,8 +36,8 @@ server.modules = (
server.port = 80
server.username = "http" # Debian and Ubuntu use www-data
server.groupname = "http"
-server.document-root = "/usr/share/cgit" # a valid docroot must exist, the
- # alias rules below do the routing
+server.document-root = "/usr/share/cgit" # a valid docroot must exist. The
+ # alias rules below do the routing.
server.pid-file = "/run/lighttpd.pid"
server.errorlog = "/var/log/lighttpd/error.log"
accesslog.filename = "/var/log/lighttpd/access.log"
@@ -76,8 +75,9 @@ $HTTP["host"] == "git.example.org" {
# Site-wide security headers are set here so they also cover the static
# assets lighttpd serves. cgit itself sends only the headers the server
# cannot supply. Those are Status, Content-Type, Content-Length and
- # Content-Disposition on downloads, a no-store Cache-Control on
- # unauthenticated responses, the auth filter's Set-Cookie, and on raw
+ # Content-Disposition on downloads, Location on redirects, a no-store
+ # Cache-Control on unauthenticated responses, the auth filter's
+ # Set-Cookie, and on raw
# repository bytes a nosniff of its own next to the stricter policy
# "default-src 'none'". Everything else, this policy included, is the
# server's job.
@@ -89,10 +89,10 @@ $HTTP["host"] == "git.example.org" {
# what cgit sent, swapping the strict policy on raw repository content
# for this looser site one. Never switch add to set.
#
- # script-src stays self because cgit loads only its own cgit.js, and
- # style-src allows inline for the diffstat bars. form-action self covers
- # the login form, the only form cgit renders. If you enable the gravatar
- # or libravatar avatar filter, add its host to img-src.
+ # form-action self covers the login form, the only form cgit renders. If
+ # you enable the gravatar or libravatar avatar filter, add its host to
+ # img-src. A head-include or repo.head-content that injects a <style>
+ # block needs 'unsafe-inline' added to style-src.
#
# Permissions-Policy refuses the browser features a git viewer never asks
# for, camera and location among them, for everything served here,
@@ -104,7 +104,7 @@ $HTTP["host"] == "git.example.org" {
# Cross-Origin-Embedder-Policy is deliberately absent because it would
# break the avatar filters mentioned above.
setenv.add-response-header = (
- "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'",
+ "Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'",
"X-Content-Type-Options" => "nosniff",
"Referrer-Policy" => "no-referrer",
"Permissions-Policy" => "accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()",
@@ -116,10 +116,8 @@ $HTTP["host"] == "git.example.org" {
# it is hard to undo once browsers have seen it.
#setenv.add-response-header += ( "Strict-Transport-Security" => "max-age=63072000; includeSubDomains" )
- # Register the cgit binary as a CGI program. The key cgit.cgi matches the
- # binary's name and the empty value means the file is itself the program,
- # with no interpreter in front of it. This is what makes lighttpd split
- # the trailing path off as PATH_INFO, so never drop it.
+ # Register the cgit binary as a CGI program. The empty value means the
+ # file is itself the program rather than input to an interpreter.
cgi.assign = ( "cgit.cgi" => "" )
# Routing. lighttpd's alias.url is first-match in declaration order, not