AgeCommit message (Collapse)AuthorLines
Mark a page behind an auth filter privateBryce Kwon-14/+15
Only the login page carried a Cache-Control, so a page an auth filter had let a visitor see could be kept by a cache shared with the next visitor. The page also varies on the cookie that got them in.
Unify the docs, samples and extensionsBryce Kwon-15/+12
Refresh the server configs and drop `unsafe-inline`Bryce Kwon-94/+71
The inline handlers and the auto-submitting selects are gone, so `script-src` no longer needs it, and t0004 now checks that the three configs pin the same policy.
Refuse unknown and spoofed hostnames in nginx.confBryce Kwon-0/+31
Rework the response headers in the server configsBryce Kwon-30/+132
Drop the Last-Modified, Expires and ETag headersBryce Kwon-1/+11
Make the server configs complete standalone filesBryce Kwon-204/+395
Reorganize the tree into vendor/ and custom/Bryce Kwon-0/+477