diff options
Diffstat (limited to 'custom/servers/lighttpd.conf')
| -rw-r--r-- | custom/servers/lighttpd.conf | 10 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 5 insertions, 5 deletions
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf index c2a478f..c81306f 100644 --- a/custom/servers/lighttpd.conf +++ b/custom/servers/lighttpd.conf @@ -75,11 +75,11 @@ $HTTP["host"] == "git.example.org" { # Site-wide security headers are set here so they also cover the static # assets lighttpd serves. cgit itself sends only the headers the server # cannot supply. Those are Status, Content-Type, Content-Length and - # Content-Disposition on downloads, Location on redirects, a no-store - # Cache-Control on unauthenticated responses, the auth filter's Set-Cookie, - # and on raw repository bytes a nosniff of its own next to the stricter - # policy "default-src 'none'". Everything else, this policy included, is - # the server's job. + # Content-Disposition on downloads, Location on redirects, a Cache-Control + # marking the login page no-store and a page behind an auth filter private, + # the auth filter's Set-Cookie, and on raw repository bytes a nosniff of + # its own next to the stricter policy "default-src 'none'". Everything + # else, this policy included, is the server's job. # # The add in add-response-header is load bearing. It appends a second # copy next to what cgit emitted, so a raw page carries both policies and |
