feat(nginx): add security headers with per-domain CSP
- Add HSTS (6 months, includeSubDomains, preload-ready) - Add X-Content-Type-Options: nosniff - Add Permissions-Policy (disable camera/mic/geolocation) - Add Cross-Origin-Resource-Policy: same-origin - Add Cross-Origin-Opener-Policy: same-origin - Add configurable Content-Security-Policy per domain Per-service CSP tuning: - SearXNG: null (handles its own CSP in settings.yml) - Forgejo: relaxed (unsafe-inline/eval for code highlighting) - Vaultwarden: relaxed (unsafe-eval for WebCrypto vault) Fixes: missing CSP, HSTS, X-Content-Type-Options headers
This commit is contained in:
parent
6354a030f0
commit
fbea02867e
4 changed files with 35 additions and 1 deletions
|
|
@ -104,6 +104,8 @@
|
|||
domains = {
|
||||
"search.ashisgreat.xyz" = {
|
||||
port = 8888;
|
||||
# SearXNG sets its own CSP in settings.yml — omit at Nginx level to avoid conflicts
|
||||
contentSecurityPolicy = null;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue