diff --git a/conf/Caddyfile b/conf/Caddyfile index 9da5272..0ba9153 100644 --- a/conf/Caddyfile +++ b/conf/Caddyfile @@ -6,7 +6,7 @@ (common) { encode gzip zstd - header { + header { Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" X-Content-Type-Options "nosniff" X-Frame-Options "DENY" @@ -16,7 +16,17 @@ Cross-Origin-Opener-Policy "same-origin" Cross-Origin-Resource-Policy "same-origin" Cross-Origin-Embedder-Policy "require-corp" + Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:" + Expect-CT "max-age=86400, enforce" } + + # Blockera kända skadliga sökvägar för alla domäner + @blocked path_regexp ^/(\.env|\.git|wp-login|robots\.txt|api/graphql|actuator/env|\.DS_Store|file6\.php|wp-.*\.php|config\.json|telescope|debug|info\.php|class-.*\.php|spawns\.php|cream1\.php|dal\.php|wp-good\.php|vx\.php|00\.php|cxs\.php|sdm\.php|whs.*\.php|wp-lvminl\.php|hoeig\.php|bajah\.php|ponxnwapemsce\.php|gk\.php|awp-careers\.php|wplogbak\.php)$ + respond @blocked 403 + + # Blockera kända botar + @blocked_bots header_regexp User-Agent (scanhawk|leakix|CensysInspect|l9scan|sqlmap|Nikto|DirBuster|OpenAI-SearchBot|oai-searchbot|Mozilla\/5\.0 \(compatible;.*\) + respond @blocked_bots 403 } test.gynther.se { @@ -46,6 +56,7 @@ sonarr.gynther.se { } jellyfin.gynther.se { + import common reverse_proxy http://jellyfin:8096 } @@ -72,15 +83,11 @@ gitea.gynther.se { import.gynther.se { import common - # Blockera kända skadliga sökvägar - @blocked path_regexp ^/(\.env|\.git|wp-login|robots\.txt|api/graphql|actuator/env|\.DS_Store|file6\.php|wp-.*\.php)$ - respond @blocked 403 - # Lägg till en standard-sida för / - handle / { - respond "Welcome to Import Service" 200 + handle / { + respond "Welcome to Import Service" 200 } - + reverse_proxy importer-api:3001 }