style-src 'self' (without unsafe-inline) silently blocks style="..." attributes introduced via innerHTML — the CSS parses fine and the attribute is present in the DOM, but the browser never applies it, so every bar rendered at its track's full width regardless of its real percentage. script-src stays locked down; this only loosens CSS, and no untrusted external content is ever rendered into a style attribute here. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
42 lines
1.6 KiB
Plaintext
42 lines
1.6 KiB
Plaintext
server {
|
|
listen 80;
|
|
listen [::]:80;
|
|
server_name scouting.gateway-gamers.net;
|
|
return 301 https://$host$request_uri;
|
|
}
|
|
|
|
server {
|
|
listen 443 ssl;
|
|
listen [::]:443 ssl;
|
|
server_name scouting.gateway-gamers.net;
|
|
|
|
root /var/www/domains/gateway-gamers.net/scouting;
|
|
index index.html;
|
|
|
|
# SSL — managed by Certbot
|
|
# ssl_certificate /etc/letsencrypt/live/scouting.gateway-gamers.net/fullchain.pem;
|
|
# ssl_certificate_key /etc/letsencrypt/live/scouting.gateway-gamers.net/privkey.pem;
|
|
# include /etc/letsencrypt/options-ssl-nginx.conf;
|
|
# ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
|
|
|
|
# Hide nginx version
|
|
server_tokens off;
|
|
|
|
# Security headers
|
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header X-Frame-Options "SAMEORIGIN" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
|
|
# style-src needs 'unsafe-inline': the app sets bar-chart widths via
|
|
# inline style="width:X%" through innerHTML, which CSP's style-src
|
|
# blocks without it (script-src stays locked down — this only affects
|
|
# CSS, and nothing here renders untrusted external content into a
|
|
# style attribute).
|
|
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://newprod-api.bestcoastpairings.com; img-src 'self' data:;" always;
|
|
|
|
location / {
|
|
try_files $uri $uri/ =404;
|
|
}
|
|
}
|