daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

_headers (2225B)


      1 # Security headers for every static response Cloudflare serves. Workers
      2 # reads this file out of the asset directory; Astro copies public/ into
      3 # dist/ verbatim, so this is where it is authored. Format and limits:
      4 # developers.cloudflare.com/workers/static-assets/headers/
      5 #
      6 # Mirrors daemon-sec's staticSecurityHeaders() with the differences this
      7 # site needs: 'wasm-unsafe-eval' and a same-origin worker for the Pagefind
      8 # search index, and data: fonts for the icon face inlined in the CSS. No
      9 # script, style or font is loaded from another origin.
     10 #
     11 # Inline scripts (the theme and page-iris bootstraps, and the modules
     12 # Astro inlines) are allowed by hash, not by 'unsafe-inline'. The
     13 # placeholder below is filled by scripts/csp-hashes.mjs at the end of
     14 # `npm run build`, so this file is a template: the served copy is
     15 # dist/_headers. Styles keep 'unsafe-inline' because Astro emits style
     16 # attributes, which no hash can cover.
     17 # img-src is open to https: because the imported sheets hotlink figures from
     18 # dozens of hosts; frame-src 'self' is for the PDF viewer on the JJ guide.
     19 /*
     20   Content-Security-Policy: default-src 'self'; base-uri 'self'; form-action 'self'; script-src 'self' __INLINE_SCRIPT_HASHES__ 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self'; font-src 'self' data:; object-src 'none'; media-src 'self'; frame-src 'self'; frame-ancestors 'none'; worker-src 'self'; upgrade-insecure-requests
     21   X-Frame-Options: DENY
     22   X-Content-Type-Options: nosniff
     23   Referrer-Policy: strict-origin-when-cross-origin
     24   Cross-Origin-Opener-Policy: same-origin
     25   Strict-Transport-Security: max-age=31536000; includeSubDomains
     26   Permissions-Policy: camera=(), microphone=(), geolocation=(), browsing-topics=()
     27   X-DNS-Prefetch-Control: off
     28   X-Permitted-Cross-Domain-Policies: none
     29 
     30 # The JJ field guide page frames its own PDF. The response for the PDF
     31 # itself must allow that, or the viewer shows nothing: frame-ancestors is
     32 # judged on the framed document, not the page framing it. A PDF runs no
     33 # script, so everything else stays closed.
     34 /pdfs/*
     35   ! X-Frame-Options
     36   ! Content-Security-Policy
     37   Content-Security-Policy: default-src 'none'; frame-ancestors 'self'