From a8f7e4639b79718b06b958bb3c06c82e97bfe31b Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 20:13:25 -1000 Subject: Mark a page behind an auth filter private Only the login page carried a Cache-Control, so a page an auth filter had let a visitor see could be kept by a cache shared with the next visitor. The page also varies on the cookie that got them in. --- custom/servers/nginx.conf | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) (limited to 'custom/servers/nginx.conf') diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf index 7049368..8d4b86f 100644 --- a/custom/servers/nginx.conf +++ b/custom/servers/nginx.conf @@ -154,10 +154,11 @@ http { # static assets nginx serves directly. cgit itself sends only the # headers the proxy cannot supply. Those are Status, Content-Type, # Content-Length and Content-Disposition on downloads, Location on - # redirects, a no-store Cache-Control on unauthenticated responses, the - # auth filter's Set-Cookie, and on raw repository bytes a nosniff of its - # own next to the stricter policy "default-src 'none'". Everything else, - # this policy included, is the proxy's job. + # redirects, a Cache-Control marking the login page no-store and a page + # behind an auth filter private, the auth filter's Set-Cookie, and on + # raw repository bytes a nosniff of its own next to the stricter policy + # "default-src 'none'". Everything else, this policy included, is the + # proxy's job. # # add_header appends and never replaces what cgit sent, so a raw page # carries both policies and the browser enforces the stricter one, -- cgit v2.8.0