diff options
context:
space:
mode:
Diffstat (limited to 'custom/servers/lighttpd.conf')
-rw-r--r--custom/servers/lighttpd.conf10
1 file changed, 5 insertions, 5 deletions
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf
index c2a478f..c81306f 100644
--- a/custom/servers/lighttpd.conf
+++ b/custom/servers/lighttpd.conf
@@ -75,11 +75,11 @@ $HTTP["host"] == "git.example.org" {
# Site-wide security headers are set here so they also cover the static
# assets lighttpd serves. cgit itself sends only the headers the server
# cannot supply. Those are Status, Content-Type, Content-Length and
- # Content-Disposition on downloads, Location on redirects, a no-store
- # Cache-Control on unauthenticated responses, the auth filter's Set-Cookie,
- # and on raw repository bytes a nosniff of its own next to the stricter
- # policy "default-src 'none'". Everything else, this policy included, is
- # the server's job.
+ # Content-Disposition on downloads, Location on redirects, a Cache-Control
+ # marking the login page no-store and a page behind an auth filter private,
+ # the auth filter's Set-Cookie, and on raw repository bytes a nosniff of
+ # its own next to the stricter policy "default-src 'none'". Everything
+ # else, this policy included, is the server's job.
#
# The add in add-response-header is load bearing. It appends a second
# copy next to what cgit emitted, so a raw page carries both policies and