server { listen 80; listen [::]:80; # ── Gitea #95 / #44 — shipped image had no security headers at all. # `always` so these are sent on error responses too, not just 200s. # # Content-Security-Policy, directive by directive: # default-src 'self' baseline: same-origin unless a directive below opens it up # script-src 'self' 'wasm-unsafe-eval' # app code is same-origin only; 'wasm-unsafe-eval' is required # for the wasm modules used for E2EE crypto and audio denoise # style-src 'self' 'unsafe-inline' # vanilla-extract (the app's CSS-in-JS) emits inline