Commit 3e8b89ec70
Verified · cmc
Layout: unified · split
linux/nginx/etc/nginx/conf.d/cleberg.net.conf +15
| @@ -20,6 +20,21 @@ server { | |||
| 20 | 20 | ||
| 21 | add_header Onion-Location "http://paske4urhs6nttrtlkuwa5cowum3fjkc6yv6kl4ncx3mjxcd77764nqd.onion$request_uri" always; | 21 | add_header Onion-Location "http://paske4urhs6nttrtlkuwa5cowum3fjkc6yv6kl4ncx3mjxcd77764nqd.onion$request_uri" always; |
| 22 | 22 | ||
| 23 | # Images live in the img.cleberg.net docroot and are served same-origin here | ||
| 24 | # so the .onion is self-contained (see the onion-containment work, 2026-08-03). | ||
| 25 | # | ||
| 26 | # This is an nginx alias, NOT a filesystem symlink, on purpose. A symlink at | ||
| 27 | # /var/www/cleberg.net/img worked but was DESTROYED by the very next deploy: | ||
| 28 | # the site deploys with `rsync --delete`, which removes anything in the | ||
| 29 | # destination that is not in the source tree. That silently 404'd every image | ||
| 30 | # on the site. An alias lives in nginx config, so no deploy can remove it. | ||
| 31 | location /img/ { | ||
| 32 | alias /var/www/img/; | ||
| 33 | # This block sets no add_header of its own, so it inherits the | ||
| 34 | # server-level security headers. Do not add one without re-including | ||
| 35 | # custom.d/security/headers_in_location.conf -- nginx does not merge. | ||
| 36 | } | ||
| 37 | |||
| 23 | location /org/ { | 38 | location /org/ { |
| 24 | internal; | 39 | internal; |
| 25 | alias /var/www/cleberg.net/org/; | 40 | alias /var/www/cleberg.net/org/; |
linux/nginx/etc/nginx/custom.d/http/content_type_maps.conf +37 −14
| @@ -53,20 +53,30 @@ map $sent_http_content_type $content_security_policy { | |||
| 53 | ~*text/(html|javascript)|application/pdf|xml "default-src 'self'; img-src 'self' data:; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'"; | 53 | ~*text/(html|javascript)|application/pdf|xml "default-src 'self'; img-src 'self' data:; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'"; |
| 54 | } | 54 | } |
| 55 | 55 | ||
| 56 | # cleberg.* only. Mirrors what the site actually loads, verified by grepping | 56 | # cleberg.* only. |
| 57 | # the served HTML: <img src> -> img.cleberg.net (151), <script src> -> | 57 | # |
| 58 | # bubbles.town (174), stylesheets -> https://cleberg.net (180, absolute). | 58 | # TIGHTENED 2026-08-03 after the weblorg source was made onion-self-contained. |
| 59 | # | 59 | # Stylesheets and images are now ROOT-RELATIVE, so they resolve to whichever |
| 60 | # `https://cleberg.net` must be allowed explicitly: the HTML uses ABSOLUTE | 60 | # origin served the page and `'self'` covers them on both clearnet and the |
| 61 | # stylesheet URLs, so on the .onion (a different origin) they are cross-origin | 61 | # .onion. Verified against the deployed HTML (181 files, parsed): **0** absolute |
| 62 | # and 'self' would block them. | 62 | # stylesheet refs, **0** absolute `img.cleberg.net` subresource refs. |
| 63 | # | 63 | # Consequently dropped: `img-src https://img.cleberg.net`, |
| 64 | # `upgrade-insecure-requests` is deliberately OMITTED: this vhost also serves | 64 | # `style-src https://cleberg.net`, `font-src https://cleberg.net`. |
| 65 | # the .onion over plain http, where UIR would upgrade same-origin subresource | 65 | # |
| 66 | # URLs to https and break them. Cloudflare already sets UIR on the clearnet | 66 | # `bubbles.town` DROPPED 2026-08-03 — the site was redeployed without its |
| 67 | # path. See the onion self-containment note in the project record. | 67 | # script. Verified against the deployed HTML: **0** `<script>` refs remain. The |
| 68 | # 174 surviving mentions are `<a href>` comment links, which browsers do not | ||
| 69 | # fetch and CSP does not govern. | ||
| 70 | # | ||
| 71 | # The site now loads **nothing** cross-origin: parsing all deployed HTML returns | ||
| 72 | # zero absolute subresources. `default-src 'self'` is therefore the whole story | ||
| 73 | # and script-src/connect-src need no host allowances at all. | ||
| 74 | # | ||
| 75 | # `upgrade-insecure-requests` is still deliberately OMITTED: this vhost also | ||
| 76 | # serves the .onion over plain http, where UIR would upgrade same-origin | ||
| 77 | # subresource URLs to https and break them. | ||
| 68 | map $sent_http_content_type $content_security_policy_cmc { | 78 | map $sent_http_content_type $content_security_policy_cmc { |
| 69 | ~*text/(html|javascript)|application/pdf|xml "default-src 'self'; img-src 'self' https://img.cleberg.net data:; script-src 'self' https://bubbles.town; connect-src 'self' https://bubbles.town; style-src 'self' https://cleberg.net; font-src 'self' https://cleberg.net; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'"; | 79 | ~*text/(html|javascript)|application/pdf|xml "default-src 'self'; img-src 'self' data:; script-src 'self'; connect-src 'self'; style-src 'self'; font-src 'self'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; object-src 'none'"; |
| 70 | } | 80 | } |
| 71 | 81 | ||
| 72 | # krz.sh only. Derived from the served HTML after the img.cleberg.net removal | 82 | # krz.sh only. Derived from the served HTML after the img.cleberg.net removal |
| @@ -141,8 +151,21 @@ map $sent_http_content_type $permissions_policy { | |||
| 141 | } | 151 | } |
| 142 | 152 | ||
| 143 | # Add Referrer-Policy for HTML documents. | 153 | # Add Referrer-Policy for HTML documents. |
| 154 | # `same-origin`, not `strict-origin-when-cross-origin`. | ||
| 155 | # | ||
| 156 | # Cloudflare's now-removed "security headers" toggle was setting `same-origin`, | ||
| 157 | # and dropping the toggle silently regressed this to nginx's weaker value. | ||
| 158 | # Restored deliberately 2026-08-03. | ||
| 159 | # | ||
| 160 | # The difference: `strict-origin-when-cross-origin` still sends the ORIGIN | ||
| 161 | # (`https://cleberg.net`) to external sites; `same-origin` sends **no referrer | ||
| 162 | # at all** cross-origin. On a site whose outbound links are the main cross-origin | ||
| 163 | # traffic, that is the meaningful setting — external hosts learn nothing about | ||
| 164 | # where the visitor came from. | ||
| 165 | # | ||
| 166 | # Same-origin navigation still sends a full referrer, so nothing internal breaks. | ||
| 144 | map $sent_http_content_type $referrer_policy { | 167 | map $sent_http_content_type $referrer_policy { |
| 145 | ~*text/(css|html|javascript)|application\/pdf|xml "strict-origin-when-cross-origin"; | 168 | ~*text/(css|html|javascript)|application\/pdf|xml "same-origin"; |
| 146 | } | 169 | } |
| 147 | 170 | ||
| 148 | # Add Cross-Origin-Policies for HTML documents. | 171 | # Add Cross-Origin-Policies for HTML documents. |