Files
gateway-gamers.net/scouting.gateway-gamers.net.conf
T
mandaloreandClaude Sonnet 5 812e81e220 fix: allow inline styles in CSP so bar-chart widths actually apply
style-src 'self' (without unsafe-inline) silently blocks style="..."
attributes introduced via innerHTML — the CSS parses fine and the
attribute is present in the DOM, but the browser never applies it,
so every bar rendered at its track's full width regardless of its
real percentage. script-src stays locked down; this only loosens
CSS, and no untrusted external content is ever rendered into a
style attribute here.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-06 10:57:56 -05:00

42 lines
1.6 KiB
Plaintext

server {
listen 80;
listen [::]:80;
server_name scouting.gateway-gamers.net;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
listen [::]:443 ssl;
server_name scouting.gateway-gamers.net;
root /var/www/domains/gateway-gamers.net/scouting;
index index.html;
# SSL — managed by Certbot
# ssl_certificate /etc/letsencrypt/live/scouting.gateway-gamers.net/fullchain.pem;
# ssl_certificate_key /etc/letsencrypt/live/scouting.gateway-gamers.net/privkey.pem;
# include /etc/letsencrypt/options-ssl-nginx.conf;
# ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
# Hide nginx version
server_tokens off;
# Security headers
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "geolocation=(), microphone=(), camera=()" always;
# style-src needs 'unsafe-inline': the app sets bar-chart widths via
# inline style="width:X%" through innerHTML, which CSP's style-src
# blocks without it (script-src stays locked down — this only affects
# CSS, and nothing here renders untrusted external content into a
# style attribute).
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self' https://newprod-api.bestcoastpairings.com; img-src 'self' data:;" always;
location / {
try_files $uri $uri/ =404;
}
}