Self-host front-end libraries, minimal sign-in header and CSP
- sign-in pages load only what they use (include_login_header.php, ajax_core.js) - every library, font and data file served from assets/vendor with pinned versions (VERSIONS.json); no CDN at runtime - Content-Security-Policy on app, sign-in and landing pages - remove httpbin Dropzone target and source-map references
This commit is contained in:
@@ -0,0 +1,12 @@
|
||||
<?php
|
||||
// Security headers for the public landing pages. Require this before any output.
|
||||
// Everything the landing pages load is self-hosted (css/, js/, webfonts/), and they
|
||||
// have no inline scripts, so scripts are limited to this origin.
|
||||
if (!headers_sent()) {
|
||||
header("Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; "
|
||||
. "font-src 'self' data:; img-src 'self' data:; connect-src 'self'; object-src 'none'; "
|
||||
. "base-uri 'self'; form-action 'self'; frame-ancestors 'self'", true);
|
||||
header('X-Content-Type-Options: nosniff', true);
|
||||
header('X-Frame-Options: SAMEORIGIN', true);
|
||||
header('Referrer-Policy: strict-origin-when-cross-origin', true);
|
||||
}
|
||||
Reference in New Issue
Block a user