From c755a0350b940101bf3d7b2e945cbfe3fa3afb61 Mon Sep 17 00:00:00 2001 From: Nils-Johan Gynther Date: Sun, 23 Aug 2026 10:26:36 +0200 Subject: [PATCH] =?UTF-8?q?Rad=20=C3=84ndring=202=20basicauth=20=E2=86=92?= =?UTF-8?q?=20basic=5Fauth=20(deprecated-varning=20i=20Caddy=20=E2=89=A5?= =?UTF-8?q?=202.8)=2012=E2=80=9317=20Tog=20bort=20X-XSS-Protection,=20Expe?= =?UTF-8?q?ct-CT=20(utfasade)=20och=20Cross-Origin-Embedder-Policy:=20requ?= =?UTF-8?q?ire-corp=20(blockerade=20gstatic-resurser)=2021=20Ut=C3=B6kad?= =?UTF-8?q?=20s=C3=B6kv=C3=A4gsblockering:=20.git/*,=20xmlrpc.php,=20wp-ad?= =?UTF-8?q?min/,=20wp-includes/,=20wp-content/,=20cgi-bin/,=20korta=20*.ph?= =?UTF-8?q?p-skannerfiler=20m.m.=20robots.txt=20blockeras=20inte=20l=C3=A4?= =?UTF-8?q?ngre=2025=20Fixade=20den=20trasiga=20regexen=20(oavslutad=20par?= =?UTF-8?q?entes)=20i=20@blocked=5Fbots=20+=20la=20till=20GitFinder,=20Roo?= =?UTF-8?q?tEvidence,=20zgrab,=20masscan,=20nuclei=20fr=C3=A5n=20loggen.?= =?UTF-8?q?=20Tog=20bort=20det=20farliga=20Mozilla/5.0=20(compatible;...)-?= =?UTF-8?q?m=C3=B6nstret=20som=20blockerade=20legitima=20klienter=2029?= =?UTF-8?q?=E2=80=9330=20robots.txt=20besvaras=20nu=20med=20Disallow:=20/?= =?UTF-8?q?=20(200)=20ist=C3=A4llet=20f=C3=B6r=20403=2037,=20105=20Flutter?= =?UTF-8?q?-anpassad=20CSP=20p=C3=A5=20recept.gynther.se=20och=20test.gynt?= =?UTF-8?q?her.se:=20till=C3=A5ter=20wasm-unsafe-eval=20+=20script/wasm=20?= =?UTF-8?q?fr=C3=A5n=20www.gstatic.com=20och=20fonter=20fr=C3=A5n=20fonts.?= =?UTF-8?q?gstatic.com=20=E2=80=94=20detta=20fixar?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- conf/Caddyfile | 19 +++++++++++++------ 1 file changed, 13 insertions(+), 6 deletions(-) diff --git a/conf/Caddyfile b/conf/Caddyfile index 0ba9153..e95ef7b 100644 --- a/conf/Caddyfile +++ b/conf/Caddyfile @@ -1,5 +1,5 @@ (auth) { - basicauth { + basic_auth { admin $2a$14$DahHUWD2cKyXJ96sH5VQwuQv1bqmIn0gsdoSaw4mofzfdNY2Y0VsO } } @@ -10,28 +10,31 @@ Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" X-Content-Type-Options "nosniff" X-Frame-Options "DENY" - X-XSS-Protection "1; mode=block" Referrer-Policy "strict-origin-when-cross-origin" Permissions-Policy "geolocation=(), microphone=(), camera=(), payment=()" Cross-Origin-Opener-Policy "same-origin" Cross-Origin-Resource-Policy "same-origin" - Cross-Origin-Embedder-Policy "require-corp" Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:" - Expect-CT "max-age=86400, enforce" } # Blockera kända skadliga sökvägar för alla domäner - @blocked path_regexp ^/(\.env|\.git|wp-login|robots\.txt|api/graphql|actuator/env|\.DS_Store|file6\.php|wp-.*\.php|config\.json|telescope|debug|info\.php|class-.*\.php|spawns\.php|cream1\.php|dal\.php|wp-good\.php|vx\.php|00\.php|cxs\.php|sdm\.php|whs.*\.php|wp-lvminl\.php|hoeig\.php|bajah\.php|ponxnwapemsce\.php|gk\.php|awp-careers\.php|wplogbak\.php)$ + @blocked path_regexp ^/(\.env|\.git(/.*)?|\.well-known/acme-challenge/.*\.php|wp-login.*|wp-admin(/.*)?|wp-includes(/.*)?|wp-content(/.*)?|xmlrpc\.php|xmrlpc\.php|api/graphql|actuator/env|\.DS_Store|cgi-bin(/.*)?|vendor/|telescope|debug|info\.php|config\.json|[a-zA-Z0-9_-]{1,12}\.php|class-.*\.php|whs.*\.php|wp-.*\.php)$ respond @blocked 403 # Blockera kända botar - @blocked_bots header_regexp User-Agent (scanhawk|leakix|CensysInspect|l9scan|sqlmap|Nikto|DirBuster|OpenAI-SearchBot|oai-searchbot|Mozilla\/5\.0 \(compatible;.*\) + @blocked_bots header_regexp User-Agent (scanhawk|leakix|CensysInspect|l9scan|sqlmap|Nikto|DirBuster|OpenAI-SearchBot|oai-searchbot|GitFinder|RootEvidence|zgrab|masscan|nuclei) respond @blocked_bots 403 + + # Svara på robots.txt istället för 403 + @robots path /robots.txt + respond @robots "User-agent: *\nDisallow: /" 200 } test.gynther.se { import auth import common + # Samma Flutter-anpassade CSP som recept.gynther.se + header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://www.gstatic.com; connect-src 'self' https://www.gstatic.com https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob:" reverse_proxy recipe-flutter:5000 } @@ -97,6 +100,10 @@ import.gynther.se { recept.gynther.se { import common + # Flutter Web (CanvasKit) kräver script/wasm/fonter från gstatic.com. + # Skriver över den strikta CSP:n från (common). + header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' https://www.gstatic.com; connect-src 'self' https://www.gstatic.com https://fonts.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob:" + # === IMPORT SERVICE (Document Converter) === # Dessa endpoints måste komma FÖRST innan backend reglerna! handle /api/recipes/import* {