Files
exploded-cluster/nginx/security-headers.conf
jwright b27417ff02 repo: remove superseded pilot files, ASCII-clean the build and nginx configs
Drops the legacy course-1 template, the two python assemblers the node
assembler replaced, and the unversioned scene manifest left over from the
manifest-<type> split - none referenced by build.sh, the assembler or the
README, and none produce build output. The v2 pages stay: the README lists
them as parked. Also converts typographic dashes to ASCII in build.sh and the
two nginx configs, and corrects an assembler comment that still pointed at the
removed python build.
2026-08-25 21:13:45 +10:00

20 lines
1.5 KiB
Plaintext

# Shared security headers. `include`d in the server block AND in every location that
# sets its own add_header - a location-level add_header REPLACES inherited headers
# rather than merging them (the classic nginx footgun).
#
# HSTS is host-scoped: NO includeSubDomains / preload, because the *.bztmon.com
# wildcard points elsewhere and forcing HTTPS estate-wide from here would be reckless.
# HTTP->HTTPS upgrade is Cloudflare's job.
add_header Strict-Transport-Security "max-age=31536000" always;
# script-src 'self' with NO 'unsafe-inline'. build.sh externalises every script and
# hard-fails if an inline <script> reaches dist/, so this holds without an exception.
# style-src needs 'unsafe-inline': GSAP animates by writing inline style attributes.
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; worker-src 'self'; manifest-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Resource-Policy "same-origin" always;