summary refs log tree commit diff
path: root/fleet
diff options
context:
space:
mode:
Diffstat (limited to 'fleet')
-rw-r--r--fleet/hosts/kaikou/gerrit.nix2
-rw-r--r--fleet/modules/web.nix3
2 files changed, 1 insertions, 4 deletions
diff --git a/fleet/hosts/kaikou/gerrit.nix b/fleet/hosts/kaikou/gerrit.nix
index ff05f2d..f97ba23 100644
--- a/fleet/hosts/kaikou/gerrit.nix
+++ b/fleet/hosts/kaikou/gerrit.nix
@@ -35,8 +35,6 @@
   services.caddy.config = ''
     review.unfathomable.blue {
       import common
-      # This is to override the stronger policy set in //modules/web.nix.
-      header Content-Security-Policy "script-src https://review.unfathomable.blue/; object-src 'none'"
       reverse_proxy localhost:8080
     }
   '';
diff --git a/fleet/modules/web.nix b/fleet/modules/web.nix
index 97b67ca..248f78b 100644
--- a/fleet/modules/web.nix
+++ b/fleet/modules/web.nix
@@ -28,8 +28,7 @@
 
         header {
           Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"
-          # TODO(V): Consider relaxing this a bit. Disabling JavaScript is bound to result in subtle breakage.
-          Content-Security-Policy "script-src 'none'; object-src 'none'"
+          # TODO(V): Define a content security policy. Make it report-only at first, to avoid breaking things.
           Permissions-Policy "interest-cohort=()"
           X-Clacks-Overhead "GNU Terry Pratchett"
         }