From 1b99463c1908037bb7dff9a766917791c25f484c Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:51:16 +0300 Subject: Security: Document the hardening and the proxy's part in it README: limit_req in the nginx sample, what HTTPS and TRUST_PROXY are for, and the auth notes cover the throttles, Sec-Fetch-Site, headers and logging. AGENTS.md records what the security pass checked and left alone, so the next one need not repeat it. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- AGENTS.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'AGENTS.md') diff --git a/AGENTS.md b/AGENTS.md index 5ffd8ba..5aec663 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -154,7 +154,11 @@ internal/web/ server.go (host router, middleware, render helpers) as well as to `reservedPageSlugs`) also get `X-Frame-Options: DENY` and a CSP of `frame-ancestors`/`base-uri`/`form-action`/`object-src` only — no `script-src`, the dashboard's inline scripts are a product - constraint. Public blog pages carry no framing rule (owner content). Flood + constraint. Public blog pages carry no framing rule (owner content). + Audited and left as is (2026-09): SQL is all parameterised (`likeEscape` + for ILIKE, `pgx.Identifier` for database names); templates are + `html/template` and the only `{{html}}` sinks are owner-authored content; + `/media` never renders a type a browser would script (`filetype.go`). Flood control for everything else stays at the reverse proxy (`limit_req`). - **Templates**: each page file is parsed together with its layout (`layouts/dashboard.html` or `layouts/blog.html` for `blog/*`) and all -- cgit v1.2.3