aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/templates/git@git.eyesin.space:/git/blogspace.git
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:49:19 +0300
committergrm <grm@eyesin.space>2026-09-18 13:49:28 +0300
commitd23fe805546e992c8033d64d7177fe1454ad7716 (patch)
tree79657033b96f852f57bac5c0bf42551a8721afa8 /internal/web/templates/git@git.eyesin.space:/git/blogspace.git
parentabc1898daebae33405688618caffa01cece3b850 (diff)
downloadblogspace-d23fe805546e992c8033d64d7177fe1454ad7716.tar.gz
blogspace-d23fe805546e992c8033d64d7177fe1454ad7716.tar.bz2
blogspace-d23fe805546e992c8033d64d7177fe1454ad7716.zip
Security: Send security headers; refuse to frame the dashboard
Pages carried no X-Content-Type-Options, no Referrer-Policy, and the dashboard could be framed by any site (clickjacking a superadmin's delete buttons). Every response now says nosniff and strict-origin-when-cross-origin, and the management paths on the root host add X-Frame-Options: DENY plus a CSP of frame-ancestors, base-uri, form-action and object-src — the directives that do not touch the dashboard's inline scripts, which are a product constraint. Blog pages get no framing rule: they are the owner's content and may be embedded on purpose. HSTS moves into the same helper. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/templates/git@git.eyesin.space:/git/blogspace.git')
0 files changed, 0 insertions, 0 deletions