daemon-sec-lotl

DÆMONBins: GTFOBins × LOLBAS × WADComs × LOOBins in one filterable catalog
git clone https://git.daemon-sec.xyz/daemon-sec-lotl.git
Log | Files | Refs | Submodules | README | LICENSE

_headers (2108B)


      1 # Security headers for every static response Cloudflare serves. Workers
      2 # reads this file out of the asset directory; Astro copies public/ into
      3 # dist/ verbatim, so this is where it is authored. Format and limits:
      4 # developers.cloudflare.com/workers/static-assets/headers/
      5 #
      6 # Mirrors daemon-sec's staticSecurityHeaders() with the differences this
      7 # site needs: 'wasm-unsafe-eval' and a same-origin worker for the Pagefind
      8 # search index, and data: fonts for the icon face inlined in the CSS. No
      9 # script, style or font is loaded from another origin.
     10 #
     11 # Inline scripts (the theme and page-iris bootstraps, the Vercel stubs, and
     12 # any module Astro inlines) are allowed by hash, not by 'unsafe-inline'.
     13 # The placeholder below is filled by scripts/csp-hashes.mjs at the end of
     14 # `npm run build`, so this file is a template: the served copy is
     15 # dist/_headers. Styles keep 'unsafe-inline' because Astro emits style
     16 # attributes, which no hash can cover.
     17 # Nothing on this site embeds another origin, so img-src and frame-src stay
     18 # closed. frame-ancestors 'self' matches vercel.json, the Vercel-side twin.
     19 /*
     20   Content-Security-Policy: default-src 'self'; base-uri 'self'; form-action 'self'; script-src 'self' __INLINE_SCRIPT_HASHES__ 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self' data:; object-src 'none'; media-src 'self'; frame-src 'none'; frame-ancestors 'self'; worker-src 'self'; upgrade-insecure-requests
     21   X-Frame-Options: SAMEORIGIN
     22   X-Content-Type-Options: nosniff
     23   Referrer-Policy: strict-origin-when-cross-origin
     24   Cross-Origin-Opener-Policy: same-origin
     25   Strict-Transport-Security: max-age=31536000; includeSubDomains
     26   Permissions-Policy: camera=(), microphone=(), geolocation=(), browsing-topics=()
     27   X-DNS-Prefetch-Control: off
     28   X-Permitted-Cross-Domain-Policies: none
     29 
     30 # Cache rules carried over from vercel.json: the search index is content-
     31 # hashed, the dataset is not.
     32 /data/index-*.json
     33   Cache-Control: public, max-age=31536000, immutable
     34 
     35 /data/techniques.json
     36   Cache-Control: public, max-age=600, must-revalidate