b27417ff02
Drops the legacy course-1 template, the two python assemblers the node assembler replaced, and the unversioned scene manifest left over from the manifest-<type> split - none referenced by build.sh, the assembler or the README, and none produce build output. The v2 pages stay: the README lists them as parked. Also converts typographic dashes to ASCII in build.sh and the two nginx configs, and corrects an assembler comment that still pointed at the removed python build.
20 lines
1.5 KiB
Plaintext
20 lines
1.5 KiB
Plaintext
# Shared security headers. `include`d in the server block AND in every location that
|
|
# sets its own add_header - a location-level add_header REPLACES inherited headers
|
|
# rather than merging them (the classic nginx footgun).
|
|
#
|
|
# HSTS is host-scoped: NO includeSubDomains / preload, because the *.bztmon.com
|
|
# wildcard points elsewhere and forcing HTTPS estate-wide from here would be reckless.
|
|
# HTTP->HTTPS upgrade is Cloudflare's job.
|
|
add_header Strict-Transport-Security "max-age=31536000" always;
|
|
|
|
# script-src 'self' with NO 'unsafe-inline'. build.sh externalises every script and
|
|
# hard-fails if an inline <script> reaches dist/, so this holds without an exception.
|
|
# style-src needs 'unsafe-inline': GSAP animates by writing inline style attributes.
|
|
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; worker-src 'self'; manifest-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests" always;
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header X-Frame-Options "DENY" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=(), interest-cohort=()" always;
|
|
add_header Cross-Origin-Opener-Policy "same-origin" always;
|
|
add_header Cross-Origin-Resource-Policy "same-origin" always;
|