diff options
context:
space:
mode:
Diffstat (limited to 'custom/servers/nginx.conf')
-rw-r--r--custom/servers/nginx.conf56
1 file changed, 45 insertions, 11 deletions
diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf
index 12d6888..f26598c 100644
--- a/custom/servers/nginx.conf
+++ b/custom/servers/nginx.conf
@@ -101,7 +101,8 @@ http {
# The site itself, written for TLS on 443. For a quick plain-HTTP test,
# change the two listen lines to port 80, delete the redirect block above,
- # and delete the http2 and ssl lines below. Everything else stays as it is.
+ # and delete the http2, ssl and Strict-Transport-Security lines below.
+ # Everything else stays as it is.
server {
listen 443 ssl;
listen [::]:443 ssl;
@@ -123,18 +124,51 @@ http {
ssl_session_timeout 1d;
ssl_session_tickets off;
- # Security headers sit here, not in cgit, because they must also cover
- # the static assets nginx serves directly. cgit loads only its own
- # /cgit.js and uses inline style on the diffstat bars, so script-src
- # stays self while style-src allows inline. always applies them to
- # error responses too. If you enable the gravatar or libravatar avatar
- # filter, add its host to img-src, for example https://www.gravatar.com
- # or https://seccdn.libravatar.org.
- add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'" always;
+ # Site-wide security headers sit here because they must also cover the
+ # static assets nginx serves directly. cgit itself sends only the
+ # headers the proxy cannot supply. Those are Status, Content-Type,
+ # Content-Length and Content-Disposition on downloads, a no-store
+ # Cache-Control on unauthenticated responses, the auth filter's
+ # Set-Cookie, and on raw repository bytes a nosniff of its own next to
+ # the stricter policy "default-src 'none'". Everything else, this
+ # policy included, is the proxy's job.
+ #
+ # add_header appends and never replaces what cgit sent, so a raw page
+ # carries both policies and the browser enforces the stricter one,
+ # while the doubled nosniff line is harmless. Keep it that way. Any
+ # construct that rewrites response headers here could strip the
+ # protection cgit puts on raw repository content.
+ #
+ # cgit loads only its own /cgit.js and uses inline style on the
+ # diffstat bars, so script-src stays self while style-src allows
+ # inline. form-action self covers the login form, the only form cgit
+ # renders. always applies them to error responses too. If you enable
+ # the gravatar or libravatar avatar filter, add its host to img-src,
+ # for example https://www.gravatar.com or https://seccdn.libravatar.org.
+ add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "no-referrer" always;
- # Enable only once you serve HTTPS exclusively, since it is hard to undo.
- #add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;
+
+ # The browser features a git viewer never asks for, camera and
+ # location among them, are refused outright for everything served
+ # here, repository files included.
+ add_header Permissions-Policy "accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), usb=()" always;
+
+ # Cross-origin isolation. The opener policy cuts any window.opener
+ # link between cgit and pages that open it, and the resource policy
+ # stops other origins from embedding what cgit serves, a hotlinked
+ # raw file for example. git clients are not browsers and ignore both,
+ # so clone and snapshot downloads keep working. The stricter
+ # Cross-Origin-Embedder-Policy is deliberately absent because it
+ # would break the avatar filters mentioned above.
+ add_header Cross-Origin-Opener-Policy "same-origin" always;
+ add_header Cross-Origin-Resource-Policy "same-origin" always;
+
+ # Two years of forced HTTPS. This config already redirects every
+ # plain request to TLS, so browsers may as well stop asking. Delete
+ # this line if you convert the vhost to plain HTTP, and know it is
+ # hard to undo once browsers have seen it.
+ add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;
# The document root is the directory that holds the static assets. cgit
# emits absolute links to /cgit.css and /cgit.png by default, so those