AgeCommit message (Collapse)AuthorLines
Mark a page behind an auth filter privateBryce Kwon-5/+5
Only the login page carried a Cache-Control, so a page an auth filter had let a visitor see could be kept by a cache shared with the next visitor. The page also varies on the cookie that got them in.
Unify the docs, samples and extensionsBryce Kwon-5/+4
Refresh the server configs and drop `unsafe-inline`Bryce Kwon-34/+26
The inline handlers and the auto-submitting selects are gone, so `script-src` no longer needs it, and t0004 now checks that the three configs pin the same policy.
Rework the response headers in the server configsBryce Kwon-11/+49
Drop the Last-Modified, Expires and ETag headersBryce Kwon-1/+5
Make the server configs complete standalone filesBryce Kwon-55/+157
Reorganize the tree into vendor/ and custom/Bryce Kwon-0/+152