-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path_headers
More file actions
33 lines (29 loc) · 2.18 KB
/
Copy path_headers
File metadata and controls
33 lines (29 loc) · 2.18 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
# Cloudflare Pages security headers—DEV-STANDARDS §12
# Served from the repo root (this site has no build step, the repo IS the output).
#
# Platform facts this file depends on—do not "clean these up":
# • Limits: 100 header rules; 2,000 characters per LINE. Never wrap the
# CSP—a wrapped line is silently dropped, taking the whole policy with it.
# • Pages injects `Access-Control-Allow-Origin: *` on static assets. We unset it.
# • ONE Content-Security-Policy block, for /*. Pages joins duplicate headers
# with a comma and comma-joined CSPs are enforced as their INTERSECTION—a
# per-page "loosened" policy tightens the site instead of relaxing it.
# • No Strict-Transport-Security here on purpose. HSTS is owned at the zone:
# SSL/TLS → Edge Certificates → HTTP Strict Transport Security.
/*
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Referrer-Policy: no-referrer
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Permissions-Policy: accelerometer=(), autoplay=(self), browsing-topics=(), camera=(), display-capture=(), encrypted-media=(), geolocation=(), gyroscope=(), idle-detection=(), local-fonts=(), magnetometer=(), microphone=(), midi=(), payment=(), publickey-credentials-get=(), screen-wake-lock=(), serial=(), usb=(), xr-spatial-tracking=()
Content-Security-Policy: default-src 'none'; script-src 'self' 'unsafe-inline' https://plausible.thompsonblack.us https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; media-src 'self'; connect-src 'self' https://plausible.thompsonblack.us; manifest-src 'self'; frame-src https://challenges.cloudflare.com https://maps.google.com https://www.google.com; base-uri 'none'; form-action 'self'; frame-ancestors 'none'
! Access-Control-Allow-Origin
# --- Indexing: pages.dev is never a canonical host (§11) ---------------------
https://:project.pages.dev/*
X-Robots-Tag: noindex, nofollow
https://:version.:project.pages.dev/*
X-Robots-Tag: noindex, nofollow
# RFC 9116 §2.3—security.txt MUST be text/plain with charset=utf-8.
/.well-known/security.txt
Content-Type: text/plain; charset=utf-8