102 Commits

Author SHA1 Message Date
Tommy
6f712a9282
Set-Cookie 2025-01-03 23:24:33 -07:00
Tommy
37dcc6ddde
Update ssl_early_data configuration 2025-01-03 23:05:02 -07:00
Tommy
3b270e4657
Remove hsts.conf from setup.sh 2025-01-03 10:00:10 -07:00
Tommy
66e7b66141
Minor reorganization 2025-01-03 09:58:24 -07:00
Tommy
2cf70896f7
Merge hsts snippet into security snippet 2025-01-03 09:57:09 -07:00
Tommy
6334ef0861
Undo 2e58482
nginx-module-headers-more requires third party repo
2025-01-03 09:48:56 -07:00
Tommy
023e2cdad3
Move Access-Control-Max-Age to security.conf 2025-01-03 09:31:47 -07:00
Tommy
8293f6f1c3
Typo Fix 2025-01-03 09:28:46 -07:00
Tommy
111a568c6e
Note X-Frame-Options obsolesence 2025-01-03 09:28:28 -07:00
Tommy
65459ad784
Add Access-Control-Max-Age 2025-01-03 09:22:33 -07:00
Tommy
1ca56b7039
Add cookie secure flag
Signed-off-by: Tommy <contact@tommytran.io>
2025-01-03 09:13:14 -07:00
Tommy
819c0e6372
Add note for credentialless 2025-01-03 08:22:55 -07:00
Tommy
b52186dcaa
Update robots.txt 2025-01-03 07:34:17 -07:00
Tommy
71a7618b1c
Use strong ciphers for proxies 2025-01-03 07:22:40 -07:00
Tommy
662d06a701
Undo 1ade01c - Split HSTS headers again
nginx-module-headers-more requires third party repo
2025-01-03 07:08:15 -07:00
Tommy
a4dd4b6237
Disable gzip 2025-01-03 06:45:40 -07:00
Tommy
30d16930fc
Remove invalid config 2025-01-03 06:38:21 -07:00
Tommy
275d68ce12
Merge default server configs 2025-01-03 06:34:57 -07:00
Tommy
1ade01cd11
Merge HSTS headers with TLS config 2025-01-03 06:27:58 -07:00
Tommy
2e584825ff
Disable sending headers on http
Signed-off-by: Tommy <contact@tommytran.io>
2025-01-03 06:24:19 -07:00
Tommy
c809ef29b2
Block dangerous X headers 2025-01-03 06:15:48 -07:00
Tommy
dbdd308ffb
Add more missing sudos
Signed-off-by: Tommy <contact@tommytran.io>
2024-12-23 04:36:33 -07:00
Tommy
1c8ea3f637
Add missing sudo
Signed-off-by: Tommy <contact@tommytran.io>
2024-12-23 04:34:03 -07:00
Tommy
8c2de79410
Add mkdir for RHEL compat 2024-12-22 23:07:25 -07:00
Tommy
edba77ba20
Fix mountpoint 2024-12-22 22:51:11 -07:00
Tommy
532df8f908
Update mountpoint name 2024-12-22 22:48:02 -07:00
Tommy
5bdbab68b6
Cleanup mountpoint handling 2024-12-22 22:24:46 -07:00
Tommy
4cefc6b16c
Add nginx-session-ticket-keys mount 2024-12-22 22:17:27 -07:00
Tommy
c27d4499be
Add missing mkdir
Signed-off-by: Tommy <contact@tommytran.io>
2024-12-22 21:53:26 -07:00
Tommy
cdf3b5858c
Typo Fix
Signed-off-by: Tommy <contact@tommytran.io>
2024-12-22 21:28:46 -07:00
Tommy
8100f6f770
Change proxy_set_header Host back to $host
Signed-off-by: Tommy <contact@tommytran.io>
2024-10-21 05:13:09 -07:00
Tommy
939977d099
Fix posix compliance
Signed-off-by: Tommy <contact@tommytran.io>
2024-10-13 15:24:14 -07:00
Tommy
6767e80e38
Rename default.conf to avoid override 2024-10-13 15:20:42 -07:00
Tommy
f6242ebdfe
Fix permissions 2024-10-13 15:16:28 -07:00
Tommy
134675cc68
Permission Fix 2024-10-13 14:52:19 -07:00
Tommy
5106e34fb6
Add add.txt & disable unnecessary logging 2024-10-13 14:46:21 -07:00
Tommy
a1708ef12b
Update robots.txt 2024-10-13 14:32:14 -07:00
Tommy
4408d67d35
Add robots handling 2024-10-13 13:46:37 -07:00
Tommy
ba554095f1
Add X-Permitted-Cross-Domain-Policies
Signed-off-by: Tommy <contact@tommytran.io>
2024-10-13 07:33:28 -07:00
Tommy
11189cffe7
Proper permission policies for WebAuthn
Signed-off-by: Tommy <contact@tommytran.io>
2024-10-13 07:30:24 -07:00
Tommy
85ce409081
Remove publickey-credentials-get=()
FIDO2 is used almost everywhere now

Signed-off-by: Tommy <contact@tommytran.io>
2024-10-13 07:27:04 -07:00
Tommy
59f31c32c6
Add server_token.conf to setup script 2024-10-13 05:52:20 -07:00
Tommy
9d671fb07e
Disable server_tokens 2024-10-13 05:49:48 -07:00
Tommy
1678b0861d
Hide X-Powered-By 2024-10-13 05:15:14 -07:00
Tommy
89b35004f2
Remove unmaintained sample 2024-10-13 05:12:17 -07:00
Tommy
fd996d1a02
Remove unnecessary comment 2024-10-13 03:41:17 -07:00
Tommy
c374b5ef86
Fix listen directives 2024-10-13 03:32:03 -07:00
Tommy
d938584c21
Add vaultwarden 2024-10-13 03:30:33 -07:00
Tommy
2db0611650
Add Nextcloud 2024-10-13 03:27:54 -07:00
Tommy
95881525c4
Avoid confusion with proxy_pass 2024-10-13 02:59:28 -07:00