Files
Inboxintel/frontend/nginx.conf
T
cesnimda 38a58871ac
CI / backend (pull_request) Successful in 52s
CI / frontend (pull_request) Successful in 12s
Security / secrets (pull_request) Successful in 3s
Security / dependencies (pull_request) Successful in 54s
fix(security): audit batch B — SPA CSP/security headers + vite upgrade
Implements AUDIT_REPORT.md M-2 and M-5:
- M-2: CSP (script-src 'self'; frame-ancestors 'none'; object-src 'none'; ...),
  nosniff, X-Frame-Options DENY, Referrer-Policy on the SPA nginx, plus gzip for
  the bundle. The inline theme bootstrap moved to /theme-init.js so script-src
  'self' holds with no inline scripts.
- M-5: vite 5 -> 8 (+ plugin-react 6) — clears the dev-only esbuild advisories;
  npm audit now reports 0 vulnerabilities including dev deps. Build verified.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 03:21:35 +02:00

46 lines
1.9 KiB
Nginx Configuration File

server {
listen 80;
server_name _;
root /usr/share/nginx/html;
index index.html;
# AUDIT M-2: security headers on the SPA. script-src 'self' works because the theme
# bootstrap lives in /theme-init.js (no inline scripts); style-src needs 'unsafe-inline'
# for React/Chart.js/grid-layout inline style attributes (low risk with script-src locked).
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self'; connect-src 'self'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;
add_header Referrer-Policy "no-referrer" always;
# Compress the SPA bundle (AUDIT perf note: ~680 KB JS).
gzip on;
gzip_types text/css application/javascript application/json image/svg+xml;
gzip_min_length 1024;
# SPA fallback.
location / {
try_files $uri $uri/ /index.html;
}
# Proxy API + auth calls to the backend container.
location /api/ {
proxy_pass http://api:8080;
proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header Cookie $http_cookie;
}
# Google OAuth2 callback + sign-out land here (not under /api) and must
# reach the backend so the cookie session is established same-origin.
location ~ ^/(signin-google|signout-google) {
proxy_pass http://api:8080;
proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header Cookie $http_cookie;
}
}