diff options
context:
space:
mode:
Diffstat (limited to '')
-rw-r--r--custom/servers/nginx.conf9
1 file changed, 5 insertions, 4 deletions
diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf
index 7049368..8d4b86f 100644
--- a/custom/servers/nginx.conf
+++ b/custom/servers/nginx.conf
@@ -154,10 +154,11 @@ http {
# static assets nginx serves directly. cgit itself sends only the
# headers the proxy cannot supply. Those are Status, Content-Type,
# Content-Length and Content-Disposition on downloads, Location on
- # redirects, a no-store Cache-Control on unauthenticated responses, the
- # auth filter's Set-Cookie, and on raw repository bytes a nosniff of its
- # own next to the stricter policy "default-src 'none'". Everything else,
- # this policy included, is the proxy's job.
+ # redirects, a Cache-Control marking the login page no-store and a page
+ # behind an auth filter private, the auth filter's Set-Cookie, and on
+ # raw repository bytes a nosniff of its own next to the stricter policy
+ # "default-src 'none'". Everything else, this policy included, is the
+ # proxy's job.
#
# add_header appends and never replaces what cgit sent, so a raw page
# carries both policies and the browser enforces the stricter one,