diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:51:16 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:51:16 +0300 |
| commit | 1b99463c1908037bb7dff9a766917791c25f484c (patch) | |
| tree | edc96c13bf3a06352e6bf0e90989a6cc525071d7 /AGENTS.md | |
| parent | 2e31733093077c00be495d5725c7930f6ac9083c (diff) | |
| download | blogspace-1b99463c1908037bb7dff9a766917791c25f484c.tar.gz blogspace-1b99463c1908037bb7dff9a766917791c25f484c.tar.bz2 blogspace-1b99463c1908037bb7dff9a766917791c25f484c.zip | |
Security: Document the hardening and the proxy's part in it
README: limit_req in the nginx sample, what HTTPS and TRUST_PROXY are
for, and the auth notes cover the throttles, Sec-Fetch-Site, headers
and logging. AGENTS.md records what the security pass checked and
left alone, so the next one need not repeat it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'AGENTS.md')
| -rw-r--r-- | AGENTS.md | 6 |
1 files changed, 5 insertions, 1 deletions
@@ -154,7 +154,11 @@ internal/web/ server.go (host router, middleware, render helpers) as well as to `reservedPageSlugs`) also get `X-Frame-Options: DENY` and a CSP of `frame-ancestors`/`base-uri`/`form-action`/`object-src` only — no `script-src`, the dashboard's inline scripts are a product - constraint. Public blog pages carry no framing rule (owner content). Flood + constraint. Public blog pages carry no framing rule (owner content). + Audited and left as is (2026-09): SQL is all parameterised (`likeEscape` + for ILIKE, `pgx.Identifier` for database names); templates are + `html/template` and the only `{{html}}` sinks are owner-authored content; + `/media` never renders a type a browser would script (`filetype.go`). Flood control for everything else stays at the reverse proxy (`limit_req`). - **Templates**: each page file is parsed together with its layout (`layouts/dashboard.html` or `layouts/blog.html` for `blog/*`) and all |
