diff options
context:
space:
mode:
Diffstat (limited to 'custom/servers')
-rw-r--r--custom/servers/apache.conf10
-rw-r--r--custom/servers/lighttpd.conf10
-rw-r--r--custom/servers/nginx.conf9
3 files changed, 15 insertions, 14 deletions
diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf
index f25c444..d95d76f 100644
--- a/custom/servers/apache.conf
+++ b/custom/servers/apache.conf
@@ -204,11 +204,11 @@ AddType text/plain .txt
# Site-wide security headers are set here so they also cover the static
# assets Apache serves. cgit itself sends only the headers the proxy
# cannot supply. Those are Status, Content-Type, Content-Length and
- # Content-Disposition on downloads, Location on redirects, a no-store
- # Cache-Control on unauthenticated responses, the auth filter's Set-Cookie,
- # and on raw repository bytes a nosniff of its own next to the stricter
- # policy "default-src 'none'". Everything else, this policy included, is
- # the proxy's job.
+ # Content-Disposition on downloads, Location on redirects, a Cache-Control
+ # marking the login page no-store and a page behind an auth filter private,
+ # the auth filter's Set-Cookie, and on raw repository bytes a nosniff of
+ # its own next to the stricter policy "default-src 'none'". Everything
+ # else, this policy included, is the proxy's job.
#
# The word setifempty is load bearing on the two headers cgit can also
# emit. "Header always set" replaces a same-named header even when the
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf
index c2a478f..c81306f 100644
--- a/custom/servers/lighttpd.conf
+++ b/custom/servers/lighttpd.conf
@@ -75,11 +75,11 @@ $HTTP["host"] == "git.example.org" {
# Site-wide security headers are set here so they also cover the static
# assets lighttpd serves. cgit itself sends only the headers the server
# cannot supply. Those are Status, Content-Type, Content-Length and
- # Content-Disposition on downloads, Location on redirects, a no-store
- # Cache-Control on unauthenticated responses, the auth filter's Set-Cookie,
- # and on raw repository bytes a nosniff of its own next to the stricter
- # policy "default-src 'none'". Everything else, this policy included, is
- # the server's job.
+ # Content-Disposition on downloads, Location on redirects, a Cache-Control
+ # marking the login page no-store and a page behind an auth filter private,
+ # the auth filter's Set-Cookie, and on raw repository bytes a nosniff of
+ # its own next to the stricter policy "default-src 'none'". Everything
+ # else, this policy included, is the server's job.
#
# The add in add-response-header is load bearing. It appends a second
# copy next to what cgit emitted, so a raw page carries both policies and
diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf
index 7049368..8d4b86f 100644
--- a/custom/servers/nginx.conf
+++ b/custom/servers/nginx.conf
@@ -154,10 +154,11 @@ http {
# static assets nginx serves directly. cgit itself sends only the
# headers the proxy cannot supply. Those are Status, Content-Type,
# Content-Length and Content-Disposition on downloads, Location on
- # redirects, a no-store Cache-Control on unauthenticated responses, the
- # auth filter's Set-Cookie, and on raw repository bytes a nosniff of its
- # own next to the stricter policy "default-src 'none'". Everything else,
- # this policy included, is the proxy's job.
+ # redirects, a Cache-Control marking the login page no-store and a page
+ # behind an auth filter private, the auth filter's Set-Cookie, and on
+ # raw repository bytes a nosniff of its own next to the stricter policy
+ # "default-src 'none'". Everything else, this policy included, is the
+ # proxy's job.
#
# add_header appends and never replaces what cgit sent, so a raw page
# carries both policies and the browser enforces the stricter one,