diff options
Diffstat (limited to 'custom/servers/nginx.conf')
| -rw-r--r-- | custom/servers/nginx.conf | 56 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 45 insertions, 11 deletions
diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf index 12d6888..f26598c 100644 --- a/custom/servers/nginx.conf +++ b/custom/servers/nginx.conf @@ -101,7 +101,8 @@ http { # The site itself, written for TLS on 443. For a quick plain-HTTP test, # change the two listen lines to port 80, delete the redirect block above, - # and delete the http2 and ssl lines below. Everything else stays as it is. + # and delete the http2, ssl and Strict-Transport-Security lines below. + # Everything else stays as it is. server { listen 443 ssl; listen [::]:443 ssl; @@ -123,18 +124,51 @@ http { ssl_session_timeout 1d; ssl_session_tickets off; - # Security headers sit here, not in cgit, because they must also cover - # the static assets nginx serves directly. cgit loads only its own - # /cgit.js and uses inline style on the diffstat bars, so script-src - # stays self while style-src allows inline. always applies them to - # error responses too. If you enable the gravatar or libravatar avatar - # filter, add its host to img-src, for example https://www.gravatar.com - # or https://seccdn.libravatar.org. - add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'" always; + # Site-wide security headers sit here because they must also cover the + # static assets nginx serves directly. cgit itself sends only the + # headers the proxy cannot supply. Those are Status, Content-Type, + # Content-Length and Content-Disposition on downloads, a no-store + # Cache-Control on unauthenticated responses, the auth filter's + # Set-Cookie, and on raw repository bytes a nosniff of its own next to + # the stricter policy "default-src 'none'". Everything else, this + # policy included, is the proxy's job. + # + # add_header appends and never replaces what cgit sent, so a raw page + # carries both policies and the browser enforces the stricter one, + # while the doubled nosniff line is harmless. Keep it that way. Any + # construct that rewrites response headers here could strip the + # protection cgit puts on raw repository content. + # + # cgit loads only its own /cgit.js and uses inline style on the + # diffstat bars, so script-src stays self while style-src allows + # inline. form-action self covers the login form, the only form cgit + # renders. always applies them to error responses too. If you enable + # the gravatar or libravatar avatar filter, add its host to img-src, + # for example https://www.gravatar.com or https://seccdn.libravatar.org. + add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'" always; add_header X-Content-Type-Options "nosniff" always; add_header Referrer-Policy "no-referrer" always; - # Enable only once you serve HTTPS exclusively, since it is hard to undo. - #add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always; + + # The browser features a git viewer never asks for, camera and + # location among them, are refused outright for everything served + # here, repository files included. + add_header Permissions-Policy "accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()" always; + + # Cross-origin isolation. The opener policy cuts any window.opener + # link between cgit and pages that open it, and the resource policy + # stops other origins from embedding what cgit serves, a hotlinked + # raw file for example. git clients are not browsers and ignore both, + # so clone and snapshot downloads keep working. The stricter + # Cross-Origin-Embedder-Policy is deliberately absent because it + # would break the avatar filters mentioned above. + add_header Cross-Origin-Opener-Policy "same-origin" always; + add_header Cross-Origin-Resource-Policy "same-origin" always; + + # Two years of forced HTTPS. This config already redirects every + # plain request to TLS, so browsers may as well stop asking. Delete + # this line if you convert the vhost to plain HTTP, and know it is + # hard to undo once browsers have seen it. + add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always; # The document root is the directory that holds the static assets. cgit # emits absolute links to /cgit.css and /cgit.png by default, so those |
