- cinny/nginx.conf: a call.chat.lotusguild.org server block that serves ONLY
/public/element-call/ (the same files chat.lotusguild.org already serves
there) and 404s everything else, including source maps and dotfiles.
- cinny/nginx-security-headers-call.conf (new snippet): frame-ancestors
https://chat.lotusguild.org instead of X-Frame-Options SAMEORIGIN, which
would block the now cross-origin parent.
- cinny/nginx-security-headers.conf: the app's Permissions-Policy delegates
autoplay/camera/display-capture/microphone to the call origin (without it
the cross-origin frame's getUserMedia is refused). Outer quotes switched to
single: the inner "origin" quotes broke nginx parsing.
Nothing changes for users until config.json sets elementCallUrl (separate
step). Snippets are installed by hand on LXC 106; nginx.conf deploys on merge.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
Applied on LXC 106 (backed up, `nginx -t`, reloaded) and recorded here:
- Security headers (incl. CSP) moved to snippets/cinny-security-headers.conf
and included at server level plus in the /sw.js, static-asset and
json/html locations. nginx drops inherited add_header in any block that
sets its own, so static assets were served without nosniff and /sw.js
without a CSP (a service worker takes its CSP from its own script).
Now every path carries all seven headers. Verified: the SW installs and
controls the page under the CSP with no violations.
- #214: CSP no longer allows fonts.googleapis.com / fonts.gstatic.com
(VT323 is self-hosted since cinny 6f250353).
- #155: the /share-target → /share 303 is now live (it was only in the
repo; the 106 matrix-deploy hook has been dead since May, so repo edits
never reached it). absolute_redirect off makes it relative.
- README: the snippet, and that 106 needs these applied by hand.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA