diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:49:19 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:49:28 +0300 |
| commit | d23fe805546e992c8033d64d7177fe1454ad7716 (patch) | |
| tree | 79657033b96f852f57bac5c0bf42551a8721afa8 /internal/i18n/git@git.eyesin.space:/git/blogspace.git | |
| parent | abc1898daebae33405688618caffa01cece3b850 (diff) | |
| download | blogspace-d23fe805546e992c8033d64d7177fe1454ad7716.tar.gz blogspace-d23fe805546e992c8033d64d7177fe1454ad7716.tar.bz2 blogspace-d23fe805546e992c8033d64d7177fe1454ad7716.zip | |
Security: Send security headers; refuse to frame the dashboard
Pages carried no X-Content-Type-Options, no Referrer-Policy, and the
dashboard could be framed by any site (clickjacking a superadmin's
delete buttons). Every response now says nosniff and
strict-origin-when-cross-origin, and the management paths on the root
host add X-Frame-Options: DENY plus a CSP of frame-ancestors, base-uri,
form-action and object-src — the directives that do not touch the
dashboard's inline scripts, which are a product constraint. Blog pages
get no framing rule: they are the owner's content and may be embedded
on purpose. HSTS moves into the same helper.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/i18n/git@git.eyesin.space:/git/blogspace.git')
0 files changed, 0 insertions, 0 deletions
