Allows the Lotus Chat client to read the Kuma status page for the homeserver status banner (LotusGuild/cinny#124).
The change:connect-src in cinny/nginx-security-headers.conf gains https://isitup.lotusguild.org. Nothing else changes.
Why it's low-risk: the client only reads public, read-only JSON (/api/status-page/matrix and /api/status-page/heartbeat/matrix), with no cookies or credentials.
Deploy by hand: the live snippet on LXC 106 (/etc/nginx/snippets/cinny-security-headers.conf) was byte-identical to this file before the change. The deploy script only installs cinny/nginx.conf, so the plan is backup → copy → nginx -t → reload, restoring the backup if nginx -t fails.
Order: merge and install this before or with the cinny PR. Without it the banner stays silent (fail-quiet); nothing breaks.
Allows the Lotus Chat client to read the Kuma status page for the homeserver status banner (LotusGuild/cinny#124).
- **The change:** `connect-src` in `cinny/nginx-security-headers.conf` gains `https://isitup.lotusguild.org`. Nothing else changes.
- **Why it's low-risk:** the client only reads public, read-only JSON (`/api/status-page/matrix` and `/api/status-page/heartbeat/matrix`), with no cookies or credentials.
- **Deploy by hand:** the live snippet on LXC 106 (`/etc/nginx/snippets/cinny-security-headers.conf`) was **byte-identical** to this file before the change. The deploy script only installs `cinny/nginx.conf`, so the plan is backup → copy → `nginx -t` → reload, restoring the backup if `nginx -t` fails.
- **Order:** merge and install this before or with the cinny PR. Without it the banner stays silent (fail-quiet); nothing breaks.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
Add https://isitup.lotusguild.org to connect-src so the client can fetch
the public status JSON (GET /api/status-page/matrix and
/api/status-page/heartbeat/matrix) for the homeserver status banner.
Read-only public JSON, no credentials; nothing else changes.
The live snippet (/etc/nginx/snippets/cinny-security-headers.conf on
LXC 106) was identical to this file before the change; install it by hand
with a backup and `nginx -t` (the deploy script only handles
cinny/nginx.conf).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
jared
merged commit 0914339180 into main2026-09-29 12:28:31 -04:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Allows the Lotus Chat client to read the Kuma status page for the homeserver status banner (LotusGuild/cinny#124).
connect-srcincinny/nginx-security-headers.confgainshttps://isitup.lotusguild.org. Nothing else changes./api/status-page/matrixand/api/status-page/heartbeat/matrix), with no cookies or credentials./etc/nginx/snippets/cinny-security-headers.conf) was byte-identical to this file before the change. The deploy script only installscinny/nginx.conf, so the plan is backup → copy →nginx -t→ reload, restoring the backup ifnginx -tfails.🤖 Generated with Claude Code
https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA