1.8 KiB
Site security policy
The generated HTML includes a baseline Content Security Policy and referrer
policy so browsers receive protection even before an edge rule is installed.
The production edge must also set the following HTTP response headers for
familyfed.ie:
Content-Security-Policy: default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; img-src 'self' data: https:; font-src 'self' data:; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline' https://static.cloudflareinsights.com; connect-src 'self' https:; frame-src https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com; form-action 'self' mailto: https:; upgrade-insecure-requests
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-site
Permissions-Policy: camera=(), geolocation=(), microphone=(), payment=(), usb=()
Referrer-Policy: strict-origin-when-cross-origin
Strict-Transport-Security: max-age=63072000; includeSubDomains
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
The rule must be scoped to http.host eq "familyfed.ie". If Plausible is
enabled on a non-default host, add that exact origin to script-src.
Origin access
The public website virtual host must accept HTTP/HTTPS traffic only from
Cloudflare's published IPv4 and IPv6 ranges. Keep the S3 deployment API on
s3-sites.bcgen.ie reachable by Forgejo runners; do not apply the website
virtual-host restriction to the S3 API listener. Authenticated Origin Pulls or
a Cloudflare Tunnel are preferable when supported by the origin proxy.
Verify the restriction from a non-Cloudflare client with:
curl --resolve familyfed.ie:443:ORIGIN_IP https://familyfed.ie/
The request must fail before an HTTP response is served, while the normal
https://familyfed.ie/ request must continue to succeed through Cloudflare.