forked from penal-colony/nixos-vps
- Add HSTS (6 months, includeSubDomains, preload-ready) - Add X-Content-Type-Options: nosniff - Add Permissions-Policy (disable camera/mic/geolocation) - Add Cross-Origin-Resource-Policy: same-origin - Add Cross-Origin-Opener-Policy: same-origin - Add configurable Content-Security-Policy per domain Per-service CSP tuning: - SearXNG: null (handles its own CSP in settings.yml) - Forgejo: relaxed (unsafe-inline/eval for code highlighting) - Vaultwarden: relaxed (unsafe-eval for WebCrypto vault) Fixes: missing CSP, HSTS, X-Content-Type-Options headers |
||
|---|---|---|
| .. | ||
| adguard.nix | ||
| backup.nix | ||
| crowdsec.nix | ||
| default.nix | ||
| forgejo.nix | ||
| nginx.nix | ||
| openclaw-config.json | ||
| openclaw-podman.nix | ||
| podman.nix | ||
| searxng.nix | ||
| system.nix | ||
| vaultwarden.nix | ||