Files
bchanot-cv/nginx-security-headers.conf
T
Bastien Chanot ba13d697a5 fix(security): unprivileged nginx + security headers on every location
- base image -> nginxinc/nginx-unprivileged:1.28-alpine, digest-pinned
  (BREAKING for the docker path: container port 80 -> 8080; compose
  mapping/healthcheck updated in the same change, cap_add dropped)
- nginx add_header inheritance fix: shared snippets file re-included in
  every location that sets Cache-Control -- previously ALL security
  headers were dropped on real responses (verified live before/after)
- server_tokens off; set_real_ip_from restricted to 127.0.0.1
- expires directives removed (duplicated Cache-Control); gzip_types
  text/html redundancy removed (nginx -t warn)
2026-07-05 14:10:55 +02:00

13 lines
986 B
Plaintext

# Security headers for bchanot.fr — included at server level AND in every
# location that declares its own add_header: nginx add_header inheritance
# is all-or-nothing (one add_header in a location drops ALL inherited
# headers), so each such location must re-include this file.
# HSTS is intentionally NOT here — it belongs to the TLS-terminating proxy.
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=(), payment=()" always;
# CSP: inline CSS + JS are allowed (project convention), fonts from Google.
add_header Content-Security-Policy "default-src 'self'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; script-src 'self' 'unsafe-inline'; img-src 'self' data:; base-uri 'self'; form-action 'self'; frame-ancestors 'self'" always;