_headers (2225B)
1 # Security headers for every static response Cloudflare serves. Workers 2 # reads this file out of the asset directory; Astro copies public/ into 3 # dist/ verbatim, so this is where it is authored. Format and limits: 4 # developers.cloudflare.com/workers/static-assets/headers/ 5 # 6 # Mirrors daemon-sec's staticSecurityHeaders() with the differences this 7 # site needs: 'wasm-unsafe-eval' and a same-origin worker for the Pagefind 8 # search index, and data: fonts for the icon face inlined in the CSS. No 9 # script, style or font is loaded from another origin. 10 # 11 # Inline scripts (the theme and page-iris bootstraps, and the modules 12 # Astro inlines) are allowed by hash, not by 'unsafe-inline'. The 13 # placeholder below is filled by scripts/csp-hashes.mjs at the end of 14 # `npm run build`, so this file is a template: the served copy is 15 # dist/_headers. Styles keep 'unsafe-inline' because Astro emits style 16 # attributes, which no hash can cover. 17 # img-src is open to https: because the imported sheets hotlink figures from 18 # dozens of hosts; frame-src 'self' is for the PDF viewer on the JJ guide. 19 /* 20 Content-Security-Policy: default-src 'self'; base-uri 'self'; form-action 'self'; script-src 'self' __INLINE_SCRIPT_HASHES__ 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self'; font-src 'self' data:; object-src 'none'; media-src 'self'; frame-src 'self'; frame-ancestors 'none'; worker-src 'self'; upgrade-insecure-requests 21 X-Frame-Options: DENY 22 X-Content-Type-Options: nosniff 23 Referrer-Policy: strict-origin-when-cross-origin 24 Cross-Origin-Opener-Policy: same-origin 25 Strict-Transport-Security: max-age=31536000; includeSubDomains 26 Permissions-Policy: camera=(), microphone=(), geolocation=(), browsing-topics=() 27 X-DNS-Prefetch-Control: off 28 X-Permitted-Cross-Domain-Policies: none 29 30 # The JJ field guide page frames its own PDF. The response for the PDF 31 # itself must allow that, or the viewer shows nothing: frame-ancestors is 32 # judged on the framed document, not the page framing it. A PDF runs no 33 # script, so everything else stays closed. 34 /pdfs/* 35 ! X-Frame-Options 36 ! Content-Security-Policy 37 Content-Security-Policy: default-src 'none'; frame-ancestors 'self'