diff --git a/cinny/nginx-security-headers-framed.conf b/cinny/nginx-security-headers-framed.conf new file mode 100644 index 0000000..d63212c --- /dev/null +++ b/cinny/nginx-security-headers-framed.conf @@ -0,0 +1,11 @@ +# Headers for the bundled Element Call page (/public/element-call/). +# Same as cinny-security-headers.conf minus the Content-Security-Policy: the app +# embeds this page in an iframe, and the app CSP's frame-ancestors 'none' (plus a +# connect-src that doesn't list the call backends) blocked it. X-Frame-Options +# SAMEORIGIN still limits framing to chat.lotusguild.org itself. +add_header X-Frame-Options SAMEORIGIN always; +add_header X-Content-Type-Options nosniff always; +add_header X-XSS-Protection "1; mode=block" always; +add_header Referrer-Policy strict-origin-when-cross-origin always; +add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always; +add_header Permissions-Policy "accelerometer=(), autoplay=(self), camera=(self), display-capture=(self), encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(), magnetometer=(), microphone=(self), midi=(), payment=(), usb=()" always; diff --git a/cinny/nginx.conf b/cinny/nginx.conf index fb311b5..2e20552 100644 --- a/cinny/nginx.conf +++ b/cinny/nginx.conf @@ -51,6 +51,23 @@ server { add_header Cache-Control "no-cache, no-store, must-revalidate" always; } + # Bundled Element Call: framed by the app itself, so it must not carry the + # app CSP (frame-ancestors 'none' blocked every web call). Same caching as + # below: HTML never cached, hashed assets for a year. + location ^~ /public/element-call/ { + include snippets/cinny-security-headers-framed.conf; + location ~* \.html$ { + include snippets/cinny-security-headers-framed.conf; + expires -1; + add_header Cache-Control "no-cache, no-store, must-revalidate" always; + } + location ~* \.(?:js|css|woff2?|png|svg|ico|webp|wasm)$ { + include snippets/cinny-security-headers-framed.conf; + expires 1y; + add_header Cache-Control "public, immutable" always; + } + } + # Cache content-addressed static assets aggressively location ~* \.(?:js|css|woff2?|png|svg|ico|webp)$ { include snippets/cinny-security-headers.conf;