AgeCommit message (Collapse)AuthorLines
Mark a page behind an auth filter privateBryce Kwon-4/+5
Only the login page carried a Cache-Control, so a page an auth filter had let a visitor see could be kept by a cache shared with the next visitor. The page also varies on the cookie that got them in.
Unify the docs, samples and extensionsBryce Kwon-5/+4
Refresh the server configs and drop `unsafe-inline`Bryce Kwon-43/+30
The inline handlers and the auto-submitting selects are gone, so `script-src` no longer needs it, and t0004 now checks that the three configs pin the same policy.
Refuse unknown and spoofed hostnames in nginx.confBryce Kwon-0/+31
Rework the response headers in the server configsBryce Kwon-11/+45
Drop the Last-Modified, Expires and ETag headersBryce Kwon-0/+6
Make the server configs complete standalone filesBryce Kwon-127/+200
Reorganize the tree into vendor/ and custom/Bryce Kwon-0/+0
Add example web server configurationsBryce Kwon-0/+193
The wiring has real pitfalls around PATH_INFO and the link base, so these ship as working commented configs. nginx needs the fcgiwrap bridge while apache and lighttpd run the CGI directly. The security headers live here rather than in cgit because they must also cover the static assets the server serves itself.