From 977be2679031d0ab5b382f2096b8d313f3291a21 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sun, 6 Sep 2026 20:58:03 -1000 Subject: Refresh the server configs and drop `unsafe-inline` The inline handlers and the auto-submitting selects are gone, so `script-src` no longer needs it, and t0004 now checks that the three configs pin the same policy. --- custom/servers/apache.conf | 60 ++++++++++++++++-------------------- custom/servers/lighttpd.conf | 32 +++++++++---------- custom/servers/nginx.conf | 73 ++++++++++++++++++-------------------------- 3 files changed, 71 insertions(+), 94 deletions(-) (limited to 'custom/servers') diff --git a/custom/servers/apache.conf b/custom/servers/apache.conf index 3c035f7..bbd3e75 100644 --- a/custom/servers/apache.conf +++ b/custom/servers/apache.conf @@ -136,9 +136,9 @@ AddType text/plain .txt Require all granted # These assets rarely change, so let browsers cache them. Keep the - # caching scoped to this directory. cgit sends no caching headers of its - # own, so a server-wide ExpiresDefault would stamp freshness onto its - # pages, fight the no-store cgit puts on the login page, and could let + # caching scoped to this directory. Ordinary cgit pages carry no caching + # headers, so a server-wide ExpiresDefault would stamp freshness onto + # them, fight the no-store cgit puts on the login page, and could let # one visitor's page be served to another from a shared cache. ExpiresActive On @@ -148,8 +148,7 @@ AddType text/plain .txt # The cgit binary. - # Allow CGI execution here. ScriptAlias implies it, stating it makes the - # intent clear. + # Allow CGI execution here. Options +ExecCGI # Run cgit.cgi as a CGI even if it is ever reached through a plain Alias # rather than ScriptAlias. @@ -159,8 +158,8 @@ AddType text/plain .txt -# This vhost only bounces plain HTTP up to HTTPS. It serves no cgit itself, -# every cgit directive lives in the HTTPS vhost below. To run without TLS for +# This vhost only bounces plain HTTP up to HTTPS. It serves no cgit itself. +# Every cgit directive lives in the HTTPS vhost below. To run without TLS for # now, convert the HTTPS vhost to port 80 and delete this whole block rather # than editing it, since deleting only the Redirect line would leave a vhost # that serves nothing. @@ -205,27 +204,25 @@ AddType text/plain .txt # Site-wide security headers are set here so they also cover the static # assets Apache serves. cgit itself sends only the headers the proxy # cannot supply. Those are Status, Content-Type, Content-Length and - # Content-Disposition on downloads, a no-store Cache-Control on - # unauthenticated responses, the auth filter's Set-Cookie, and on raw + # Content-Disposition on downloads, Location on redirects, a no-store + # Cache-Control on unauthenticated responses, the auth filter's + # Set-Cookie, and on raw # repository bytes a nosniff of its own next to the stricter policy # "default-src 'none'". Everything else, this policy included, is the # proxy's job. # # The word setifempty is load bearing on the two headers cgit can also # emit. "Header always set" replaces a same-named header even when the - # CGI sent it, which was verified against Apache 2.4.67 and would swap - # the strict policy on raw repository content for this looser site one. - # setifempty yields to whatever cgit sent and still covers every response - # without one, the HTML pages, the static assets, and with always also - # Apache's own error pages. Referrer-Policy stays a plain set because - # cgit never emits it, so there is nothing to overwrite. + # CGI sent it, which would swap the strict policy on raw repository + # content for this looser site one. setifempty yields to whatever cgit + # sent. Referrer-Policy stays a plain set because cgit never emits it. # - # script-src stays self because cgit loads only its own cgit.js, and - # style-src allows inline for the diffstat bars. form-action self covers - # the login form, the only form cgit renders. If you enable the gravatar - # or libravatar avatar filter, add its host to img-src, for example - # https://www.gravatar.com. - Header always setifempty Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'" + # form-action self covers the login form, the only form cgit renders. If + # you enable the gravatar or libravatar avatar filter, add its host to + # img-src, for example https://www.gravatar.com. A head-include or + # repo.head-content that injects a