| Age | Commit message (Collapse) | Author | Lines |
|---|---|---|---|
| Mark a page behind an auth filter private | Bryce Kwon | -14/+15 | |
| Only the login page carried a Cache-Control, so a page an auth filter had let a visitor see could be kept by a cache shared with the next visitor. The page also varies on the cookie that got them in. | |||
| Unify the docs, samples and extensions | Bryce Kwon | -15/+12 | |
| Refresh the server configs and drop `unsafe-inline` | Bryce Kwon | -94/+71 | |
| The inline handlers and the auto-submitting selects are gone, so `script-src` no longer needs it, and t0004 now checks that the three configs pin the same policy. | |||
| Refuse unknown and spoofed hostnames in nginx.conf | Bryce Kwon | -0/+31 | |
| Rework the response headers in the server configs | Bryce Kwon | -30/+132 | |
| Drop the Last-Modified, Expires and ETag headers | Bryce Kwon | -1/+11 | |
| Make the server configs complete standalone files | Bryce Kwon | -204/+395 | |
| Reorganize the tree into vendor/ and custom/ | Bryce Kwon | -0/+477 | |
