_headers (2108B)
1 # Security headers for every static response Cloudflare serves. Workers 2 # reads this file out of the asset directory; Astro copies public/ into 3 # dist/ verbatim, so this is where it is authored. Format and limits: 4 # developers.cloudflare.com/workers/static-assets/headers/ 5 # 6 # Mirrors daemon-sec's staticSecurityHeaders() with the differences this 7 # site needs: 'wasm-unsafe-eval' and a same-origin worker for the Pagefind 8 # search index, and data: fonts for the icon face inlined in the CSS. No 9 # script, style or font is loaded from another origin. 10 # 11 # Inline scripts (the theme and page-iris bootstraps, the Vercel stubs, and 12 # any module Astro inlines) are allowed by hash, not by 'unsafe-inline'. 13 # The placeholder below is filled by scripts/csp-hashes.mjs at the end of 14 # `npm run build`, so this file is a template: the served copy is 15 # dist/_headers. Styles keep 'unsafe-inline' because Astro emits style 16 # attributes, which no hash can cover. 17 # Nothing on this site embeds another origin, so img-src and frame-src stay 18 # closed. frame-ancestors 'self' matches vercel.json, the Vercel-side twin. 19 /* 20 Content-Security-Policy: default-src 'self'; base-uri 'self'; form-action 'self'; script-src 'self' __INLINE_SCRIPT_HASHES__ 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; font-src 'self' data:; object-src 'none'; media-src 'self'; frame-src 'none'; frame-ancestors 'self'; worker-src 'self'; upgrade-insecure-requests 21 X-Frame-Options: SAMEORIGIN 22 X-Content-Type-Options: nosniff 23 Referrer-Policy: strict-origin-when-cross-origin 24 Cross-Origin-Opener-Policy: same-origin 25 Strict-Transport-Security: max-age=31536000; includeSubDomains 26 Permissions-Policy: camera=(), microphone=(), geolocation=(), browsing-topics=() 27 X-DNS-Prefetch-Control: off 28 X-Permitted-Cross-Domain-Policies: none 29 30 # Cache rules carried over from vercel.json: the search index is content- 31 # hashed, the dataset is not. 32 /data/index-*.json 33 Cache-Control: public, max-age=31536000, immutable 34 35 /data/techniques.json 36 Cache-Control: public, max-age=600, must-revalidate