My Nix Configuration

[systems.prefect] caddy: set some security headers

pyrox.dev 30b902e7 b8ff31ea

verified
Changed files
+12
systems
x86_64-linux
prefect
services
+12
systems/x86_64-linux/prefect/services/Caddyfile
···
header /.well-known/openpgpkey/hu/* application/octet-stream
respond /.well-known/openpgpkey/*/policy 200
header /.well-known/fursona Content-Type application/json
+
header {
+
X-Content-Type-Options nosniff
+
Permissions-Policy accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), unload=(),
+
Permissions-Policy +display-capture=(), encrypted-media=(), fullscreen=(), geolocation=(),
+
Permissions-Policy +gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(),
+
Permissions-Policy +payment=(), picture-in-picture=(), publickey-credentials-get=(), screen-wake-lock=(),
+
Permissions-Policy +sync-xhr=(self), usb=(), web-share=(), xr-spatial-tracking=(), clipboard-read=(),
+
Permissions-Policy +clipboard-write=(), gamepad=(), hid=(), idle-detection=(), interest-cohort=(), serial=()
+
X-Frame-Options SAMEORIGIN
+
Referrer-Policy origin
+
-Server
+
}
file_server {
root /var/www/blog
hide .git