Files
warmbly/web/nginx-security-headers.conf

20 lines
1.2 KiB
Plaintext

# Security response headers for the dashboard shell and its assets.
#
# This file is included once per location rather than set once at the server
# level, because nginx only inherits add_header from an outer block when the
# inner block declares none of its own. Every location here sets Cache-Control,
# so a server-level declaration would be silently dropped in exactly the places
# that serve the app.
#
# No script-src or connect-src: the API origin, the analytics host and the
# billing host are runtime configuration (config.js is rewritten by the
# container entrypoint), so an allowlist compiled into the image would break a
# self-host that points the dashboard somewhere else. What is pinned here is
# everything that does not depend on that configuration.
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), interest-cohort=()" always;
add_header Content-Security-Policy "frame-ancestors 'none'; object-src 'none'; base-uri 'none'; form-action 'self'" always;
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;