aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:51:16 +0300
committergrm <grm@eyesin.space>2026-09-18 13:51:16 +0300
commit1b99463c1908037bb7dff9a766917791c25f484c (patch)
treeedc96c13bf3a06352e6bf0e90989a6cc525071d7 /AGENTS.md
parent2e31733093077c00be495d5725c7930f6ac9083c (diff)
downloadblogspace-1b99463c1908037bb7dff9a766917791c25f484c.tar.gz
blogspace-1b99463c1908037bb7dff9a766917791c25f484c.tar.bz2
blogspace-1b99463c1908037bb7dff9a766917791c25f484c.zip
Security: Document the hardening and the proxy's part in it
README: limit_req in the nginx sample, what HTTPS and TRUST_PROXY are for, and the auth notes cover the throttles, Sec-Fetch-Site, headers and logging. AGENTS.md records what the security pass checked and left alone, so the next one need not repeat it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md6
1 files changed, 5 insertions, 1 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 5ffd8ba..5aec663 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -154,7 +154,11 @@ internal/web/ server.go (host router, middleware, render helpers)
as well as to `reservedPageSlugs`) also get `X-Frame-Options: DENY` and
a CSP of `frame-ancestors`/`base-uri`/`form-action`/`object-src` only —
no `script-src`, the dashboard's inline scripts are a product
- constraint. Public blog pages carry no framing rule (owner content). Flood
+ constraint. Public blog pages carry no framing rule (owner content).
+ Audited and left as is (2026-09): SQL is all parameterised (`likeEscape`
+ for ILIKE, `pgx.Identifier` for database names); templates are
+ `html/template` and the only `{{html}}` sinks are owner-authored content;
+ `/media` never renders a type a browser would script (`filetype.go`). Flood
control for everything else stays at the reverse proxy (`limit_req`).
- **Templates**: each page file is parsed together with its layout
(`layouts/dashboard.html` or `layouts/blog.html` for `blog/*`) and all