diff --git a/conf/Caddyfile b/conf/Caddyfile index 0ba9153..e95ef7b 100644 --- a/conf/Caddyfile +++ b/conf/Caddyfile @@ -1,5 +1,5 @@ (auth) { - basicauth { + basic_auth { admin $2a$14$DahHUWD2cKyXJ96sH5VQwuQv1bqmIn0gsdoSaw4mofzfdNY2Y0VsO } } @@ -10,28 +10,31 @@ Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" X-Content-Type-Options "nosniff" X-Frame-Options "DENY" - X-XSS-Protection "1; mode=block" Referrer-Policy "strict-origin-when-cross-origin" Permissions-Policy "geolocation=(), microphone=(), camera=(), payment=()" Cross-Origin-Opener-Policy "same-origin" Cross-Origin-Resource-Policy "same-origin" - Cross-Origin-Embedder-Policy "require-corp" Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:" - Expect-CT "max-age=86400, enforce" } # Blockera kända skadliga sökvägar för alla domäner - @blocked path_regexp ^/(\.env|\.git|wp-login|robots\.txt|api/graphql|actuator/env|\.DS_Store|file6\.php|wp-.*\.php|config\.json|telescope|debug|info\.php|class-.*\.php|spawns\.php|cream1\.php|dal\.php|wp-good\.php|vx\.php|00\.php|cxs\.php|sdm\.php|whs.*\.php|wp-lvminl\.php|hoeig\.php|bajah\.php|ponxnwapemsce\.php|gk\.php|awp-careers\.php|wplogbak\.php)$ + @blocked path_regexp ^/(\.env|\.git(/.*)?|\.well-known/acme-challenge/.*\.php|wp-login.*|wp-admin(/.*)?|wp-includes(/.*)?|wp-content(/.*)?|xmlrpc\.php|xmrlpc\.php|api/graphql|actuator/env|\.DS_Store|cgi-bin(/.*)?|vendor/|telescope|debug|info\.php|config\.json|[a-zA-Z0-9_-]{1,12}\.php|class-.*\.php|whs.*\.php|wp-.*\.php)$ respond @blocked 403 # Blockera kända botar - @blocked_bots header_regexp User-Agent (scanhawk|leakix|CensysInspect|l9scan|sqlmap|Nikto|DirBuster|OpenAI-SearchBot|oai-searchbot|Mozilla\/5\.0 \(compatible;.*\) + @blocked_bots header_regexp User-Agent (scanhawk|leakix|CensysInspect|l9scan|sqlmap|Nikto|DirBuster|OpenAI-SearchBot|oai-searchbot|GitFinder|RootEvidence|zgrab|masscan|nuclei) respond @blocked_bots 403 + + # Svara på robots.txt istället för 403 + @robots path /robots.txt + respond @robots "User-agent: *\nDisallow: /" 200 } test.gynther.se { import auth import common + # Samma Flutter-anpassade CSP som recept.gynther.se + header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://www.gstatic.com; connect-src 'self' https://www.gstatic.com https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob:" reverse_proxy recipe-flutter:5000 } @@ -97,6 +100,10 @@ import.gynther.se { recept.gynther.se { import common + # Flutter Web (CanvasKit) kräver script/wasm/fonter från gstatic.com. + # Skriver över den strikta CSP:n från (common). + header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://www.gstatic.com; connect-src 'self' https://www.gstatic.com https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob:" + # === IMPORT SERVICE (Document Converter) === # Dessa endpoints måste komma FÖRST innan backend reglerna! handle /api/recipes/import* {