cinny CSP: allow the Kuma status page (cinny #124) #16

Merged
jared merged 1 commits from csp-kuma-status into main 2026-09-29 12:28:31 -04:00
Owner

Allows the Lotus Chat client to read the Kuma status page for the homeserver status banner (LotusGuild/cinny#124).

  • The change: connect-src in cinny/nginx-security-headers.conf gains https://isitup.lotusguild.org. Nothing else changes.
  • Why it's low-risk: the client only reads public, read-only JSON (/api/status-page/matrix and /api/status-page/heartbeat/matrix), with no cookies or credentials.
  • Deploy by hand: the live snippet on LXC 106 (/etc/nginx/snippets/cinny-security-headers.conf) was byte-identical to this file before the change. The deploy script only installs cinny/nginx.conf, so the plan is backup → copy → nginx -t → reload, restoring the backup if nginx -t fails.
  • Order: merge and install this before or with the cinny PR. Without it the banner stays silent (fail-quiet); nothing breaks.

🤖 Generated with Claude Code

https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA

Allows the Lotus Chat client to read the Kuma status page for the homeserver status banner (LotusGuild/cinny#124). - **The change:** `connect-src` in `cinny/nginx-security-headers.conf` gains `https://isitup.lotusguild.org`. Nothing else changes. - **Why it's low-risk:** the client only reads public, read-only JSON (`/api/status-page/matrix` and `/api/status-page/heartbeat/matrix`), with no cookies or credentials. - **Deploy by hand:** the live snippet on LXC 106 (`/etc/nginx/snippets/cinny-security-headers.conf`) was **byte-identical** to this file before the change. The deploy script only installs `cinny/nginx.conf`, so the plan is backup → copy → `nginx -t` → reload, restoring the backup if `nginx -t` fails. - **Order:** merge and install this before or with the cinny PR. Without it the banner stays silent (fail-quiet); nothing breaks. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
jared added 1 commit 2026-09-29 12:09:04 -04:00
cinny CSP: allow the app to read the Kuma status page (cinny #124)
Lint / Shell (shellcheck) (push) Successful in 17s
Lint / JS (eslint) (push) Successful in 12s
Lint / No secrets in webhook configs (push) Successful in 7s
Lint / Landing page is rendered (matrix (push) Successful in 7s
Lint / Python (ruff) (push) Successful in 7s
Lint / Python deps (pip-audit) (push) Successful in 45s
Lint / Secret scan (gitleaks) (push) Successful in 7s
Lint / Shell (shellcheck) (pull_request) Successful in 12s
Lint / JS (eslint) (pull_request) Successful in 11s
Lint / No secrets in webhook configs (pull_request) Successful in 7s
Lint / Landing page is rendered (matrix (pull_request) Successful in 10s
Lint / Python (ruff) (pull_request) Successful in 8s
Lint / Python deps (pip-audit) (pull_request) Successful in 57s
Lint / Secret scan (gitleaks) (pull_request) Successful in 8s
9fcbd410f2
Add https://isitup.lotusguild.org to connect-src so the client can fetch
the public status JSON (GET /api/status-page/matrix and
/api/status-page/heartbeat/matrix) for the homeserver status banner.
Read-only public JSON, no credentials; nothing else changes.

The live snippet (/etc/nginx/snippets/cinny-security-headers.conf on
LXC 106) was identical to this file before the change; install it by hand
with a backup and `nginx -t` (the deploy script only handles
cinny/nginx.conf).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
jared merged commit 0914339180 into main 2026-09-29 12:28:31 -04:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: LotusGuild/matrix#16