# Security response headers for the dashboard shell and its assets. # # This file is included once per location rather than set once at the server # level, because nginx only inherits add_header from an outer block when the # inner block declares none of its own. Every location here sets Cache-Control, # so a server-level declaration would be silently dropped in exactly the places # that serve the app. # # No script-src or connect-src: the API origin, the analytics host and the # billing host are runtime configuration (config.js is rewritten by the # container entrypoint), so an allowlist compiled into the image would break a # self-host that points the dashboard somewhere else. What is pinned here is # everything that does not depend on that configuration. add_header X-Content-Type-Options "nosniff" always; add_header X-Frame-Options "DENY" always; add_header Referrer-Policy "strict-origin-when-cross-origin" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), interest-cohort=()" always; add_header Content-Security-Policy "frame-ancestors 'none'; object-src 'none'; base-uri 'none'; form-action 'self'" always; add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;