| Age | Commit message (Collapse) | Author | Lines |
|
Only the login page carried a Cache-Control, so a page an auth filter
had let a visitor see could be kept by a cache shared with the next
visitor. The page also varies on the cookie that got them in.
|
|
|
|
The inline handlers and the auto-submitting selects are gone, so
`script-src` no longer needs it, and t0004 now checks that the three
configs pin the same policy.
|
|
|
|
|
|
|
|
|
|
|
|
The wiring has real pitfalls around PATH_INFO and the link base, so
these ship as working commented configs. nginx needs the fcgiwrap
bridge while apache and lighttpd run the CGI directly. The security
headers live here rather than in cgit because they must also cover
the static assets the server serves itself.
|